The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade sulu/sulu to version 2.6.25, 3.0.8 or higher.
sulu/sulu is a highly extensible open-source PHP content management system based on the Symfony framework.
Affected versions of this package are vulnerable to SQL Injection via the categories query parameter in the Smart Content category filter. An attacker can infer the existence of, and disclose, content nodes they should not access, or cause resource-intensive queries and errors, by injecting crafted input into the parameter. This is only exploitable if a public page renders a Smart Content element with category filtering enabled.
This vulnerability can be mitigated by manually casting each ID to an integer where it is concatenated into the category (and, defensively, tag and audience-targeting) WHERE clause in the content Smart Content query builder, or by disabling category filtering on publicly reachable Smart Content elements until the patch is applied.