{"id":"CVE-2021-43836","aliases":["GHSA-vx6j-pjrh-vgjh"],"url":"https://o3.security/vulnerability/CVE-2021-43836","summary":"PHP file inclusion in the Sulu admin panel","details":"Sulu is an open-source PHP content management system based on the Symfony framework. In affected versions an attacker can read arbitrary local files via a PHP file include. In a default configuration this also leads to remote code execution. The problem is patched with the Versions 1.6.44, 2.2.18, 2.3.8, 2.4.0. For users unable to upgrade overwrite the service `sulu_route.generator.expression_token_provider` and wrap the translator before passing it to the expression language.","published":"2021-12-15T20:15:08.733Z","modified":"2026-08-07T17:03:07.636282Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"1.6.44"},{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.2.18"},{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.3.8"},{"ecosystem":"Packagist","name":"sulu/sulu","fixedVersion":"2.4.0"}],"fix":{"url":"https://github.com/sulu/sulu/commit/9c948f9ce350c68b53af8c3910e2cefc7f722b54","label":"sulu/sulu@9c948f9"},"references":[{"type":"ADVISORY","url":"https://github.com/sulu/sulu/security/advisories/GHSA-vx6j-pjrh-vgjh"},{"type":"FIX","url":"https://github.com/sulu/sulu/commit/9c948f9ce350c68b53af8c3910e2cefc7f722b54"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T17:03:07.636282Z"}}