sulu/sulu is vulnerable to Insecure Direct Object Reference (IDOR)
54
Medium Risk
The media move operation validates permissions against the collection identifier supplied in the request instead of the media item's real source collection. An authenticated backend user with edit rights on one collection can move media out of another collection they cannot access by naming their own collection in the request. This grants unauthorized access to and reorganization of protected media. The fix checks edit permissions on both the media's actual source collection and the destination collection before performing the move.
You are affected if you are using a version that falls within the vulnerable range and you rely on collection-level permissions to restrict access to media.
sulu/sulu is vulnerable to Insecure Direct Object Reference (IDOR) in versions 0.0.1 - 2.6.24 and 3.0.0 - 3.0.7.
Upgrade the sulu/sulu library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant