CVE-2025-47778

Source
https://cve.org/CVERecord?id=CVE-2025-47778
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47778.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-47778
Aliases
Published
2025-05-14T15:29:08.187Z
Modified
2026-04-10T05:27:35.382237Z
Severity
  • 6.1 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U CVSS Calculator
Summary
Sulu vulnerable to XXE in SVG File upload Inspector
Details

Sulu is an open-source PHP content management system based on the Symfony framework. Starting in versions 2.5.21, 2.6.5, and 3.0.0-alpha1, an admin user can upload SVG which may load external data via XML DOM library. This can be used for insecure XML External Entity References. The problem has been patched in versions 2.6.9, 2.5.25, and 3.0.0-alpha3. As a workaround, one may patch the effect file src/Sulu/Bundle/MediaBundle/FileInspector/SvgFileInspector.php manually.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47778.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-611"
    ]
}
References

Affected packages

Git / github.com/sulu/sulu

Affected ranges

Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.5.21"
        },
        {
            "fixed": "2.5.25"
        }
    ]
}
Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.6.5"
        },
        {
            "fixed": "2.6.9"
        }
    ]
}
Type
GIT
Repo
https://github.com/sulu/sulu
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.0.0-alpha1"
        },
        {
            "fixed": "3.0.0-alpha3"
        }
    ]
}

Affected versions

2.*
2.5.21
2.5.22
2.5.23
2.5.24
2.6.5
2.6.6
2.6.7
2.6.8
3.*
3.0.0-alpha1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-47778.json"