VDB
Sign up
MEDIUM6.1

GHSA-rrvc-c7xg-7cf3

TokenController formName not sanitized in hidden input

Quick fix

GHSA-rrvc-c7xg-7cf3 — sulu/form-bundle: upgrade to the fixed version with the command below.

composer require sulu/form-bundle:^2.5.3

Details

### Impact

TokenController get parameter formName not sanitized in returned input field leads to XSS.

_What kind of vulnerability is it? Who is impacted?_

### Patches

_Has the problem been patched? What versions should users upgrade to?_

### Workarounds

_Is there a way for users to fix or remediate the vulnerability without upgrading?_

Create a custom Symfony Request listener which checks for the get value of `form` for the TokenController and if not valid stop the request dispatching and return a error status code.

### References

_Are there any links users can visit to find out more?_

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/sulu/form-bundle
Introduced in: 2.0.0Fixed in: 2.5.3
Fixcomposer require sulu/form-bundle:^2.5.3

References