VDB
Sign up
MEDIUM

GHSA-jg26-q8hg-3pq4

Sulu: JCR-SQL2 injection via `categories` query parameter (unauthenticated)

Quick fix

GHSA-jg26-q8hg-3pq4 — sulu/sulu: upgrade to the fixed version with the command below.

composer require sulu/sulu:^2.6.25

Details

### Impact

An unauthenticated JCR-SQL2 injection exists in the Smart Content category filter of the 2.x content query builder.

Category IDs supplied through the public `?categories=` query parameter are only trimmed and are then concatenated directly into a JCR-SQL2 `WHERE` clause, without the numeric validation that the equivalent tag filter already performs. Any public page that renders a Smart Content element with category filtering enabled evaluates this parameter, so no authentication or special configuration beyond a category-filtered content block is required.

An anonymous visitor can therefore:

- inject boolean conditions to infer the existence of, and disclose, content nodes they should not see (for example unpublished pages) via blind boolean-based extraction; and - submit malformed query fragments that cause query errors or resource-intensive queries, degrading availability.

Because the sink is a JCR-SQL2 query, the impact is limited to reading and enumerating content-repository nodes and to error/denial-of-service conditions; it cannot be used to modify data through this path.

### Patches

Fixed in **2.6.25 and 3.0.8**. Category, tag, and audience-target-group IDs are now cast to integers before they are used in the JCR-SQL2 query, so no attacker-controlled characters can reach the query.

### Workarounds

If you cannot upgrade immediately:

- Apply the fix manually — cast each ID to an integer where it is concatenated into the category (and, defensively, tag and audience-targeting) `WHERE` clause in the content Smart Content query builder. - Alternatively, disable category filtering on publicly reachable Smart Content elements until the patch is applied.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sulu/sulu
Introduced in: 0Fixed in: 2.6.25
Fixcomposer require sulu/sulu:^2.6.25
Packagist/sulu/sulu
Introduced in: 3.0.0Fixed in: 3.0.8
Fixcomposer require sulu/sulu:^3.0.8

References