GHSA-rrvc-c7xg-7cf3
TokenController formName not sanitized in hidden input
Quick fix
GHSA-rrvc-c7xg-7cf3 — sulu/form-bundle: upgrade to the fixed version with the command below.
composer require sulu/form-bundle:^2.5.3Details
### Impact
TokenController get parameter formName not sanitized in returned input field leads to XSS.
_What kind of vulnerability is it? Who is impacted?_
### Patches
_Has the problem been patched? What versions should users upgrade to?_
### Workarounds
_Is there a way for users to fix or remediate the vulnerability without upgrading?_
Create a custom Symfony Request listener which checks for the get value of `form` for the TokenController and if not valid stop the request dispatching and return a error status code.
### References
_Are there any links users can visit to find out more?_
Are you affected?
Enter the version of the package you're using.
Affected packages
2.0.0Fixed in: 2.5.3composer require sulu/form-bundle:^2.5.3