Sulu, an open-source PHP content management system built on Symfony, used a weak cryptographic hash algorithm for password reset token and API key generation in versions prior to 2.6.23 and 3.0.6. The weakness in the hashing mechanism could allow attackers to predict or reverse-engineer sensitive tokens and keys, potentially leading to unauthorized account access or API abuse. The issue is classified unde [truncated]
A vulnerability was found in Sulu, an open-source PHP content management system based on the Symfony framework. From versions 1.0.0 to before 2.6.22, and 3.0.0 to before 3.0.5, a user with permission for the Sulu Admin via at least one role could have access to the sub-entities of contacts via the admin API without even having permission for contacts. This issue has been patched in versions 2.6.22 and 3.0.5.