{"id":"GHSA-rrvc-c7xg-7cf3","summary":"TokenController formName not sanitized in hidden input","details":"### Impact\n\nTokenController get parameter formName not sanitized in returned input field leads to XSS.\n\n_What kind of vulnerability is it? Who is impacted?_\n\n### Patches\n\n_Has the problem been patched? What versions should users upgrade to?_\n\n### Workarounds\n\n_Is there a way for users to fix or remediate the vulnerability without upgrading?_\n\nCreate a custom Symfony Request listener which checks for the get value of `form` for the TokenController and if not valid stop the request dispatching and return a error status code.\n\n### References\n\n_Are there any links users can visit to find out more?_\n","aliases":["CVE-2024-37156"],"modified":"2026-09-10T03:50:15.786393544Z","published":"2024-06-06T21:36:40Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-06-06T21:36:40Z","nvd_published_at":"2024-06-06T16:15:13Z","cwe_ids":["CWE-79","CWE-80"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/sulu/SuluFormBundle/security/advisories/GHSA-rrvc-c7xg-7cf3"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-37156"},{"type":"WEB","url":"https://github.com/sulu/SuluFormBundle/commit/3f341b71a7309cbc8fd2c5bff894c654d1679b17"},{"type":"PACKAGE","url":"https://github.com/sulu/SuluFormBundle"}],"affected":[{"package":{"name":"sulu/form-bundle","ecosystem":"Packagist","purl":"pkg:composer/sulu/form-bundle"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"2.0.0"},{"fixed":"2.5.3"}]}],"versions":["2.0.0","2.1.0","2.1.1","2.1.2","2.1.3","2.2.0","2.2.1","2.3.0","2.4.0","2.5.0","2.5.1","2.5.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/06/GHSA-rrvc-c7xg-7cf3/GHSA-rrvc-c7xg-7cf3.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}