Skip to content

Sulu RCE Gadget Chain #219

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open

Sulu RCE Gadget Chain #219

wants to merge 2 commits into from

Conversation

mcdruid
Copy link
Contributor

@mcdruid mcdruid commented Jun 13, 2025

This is the same gadget, but there are 3 variants because rector has changed the namespace of one of the classes over the last several versions.

I've put all of the classes / gadgets into one file and included it from the other two variants. I've also left commented out references to other classes in the chains in order to make it clear what the differences are.

I'm happy for all of that to be arranged in a different way / cleaned up according to the preference of the maintainers.

The main exploitable class has just had protection against this added:

GHSA-x3c7-22c8-prg7

We may need to update the versions in these gadget chains depending on which branches the fix is pulled into.

mcdruid added 2 commits June 13, 2025 08:12
namespaces for different versions - will convert to different gadgets
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant