CVE-2024-57610
- EPSS 3.37%
- Veröffentlicht 06.02.2025 18:15:32
- Zuletzt bearbeitet 19.09.2025 19:07:05
A rate limiting issue in Sylius v2.0.2 allows a remote attacker to perform unrestricted brute-force attacks on user accounts, significantly increasing the risk of account compromise and denial of service for legitimate users. The Supplier's position ...
CVE-2021-3841
- EPSS 0.11%
- Veröffentlicht 15.11.2024 11:15:05
- Zuletzt bearbeitet 19.11.2024 17:11:49
sylius/sylius versions prior to 1.9.10, 1.10.11, and 1.11.2 are vulnerable to stored cross-site scripting (XSS) through SVG files. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of the user's brows...
CVE-2024-40633
- EPSS 0.24%
- Veröffentlicht 17.07.2024 18:15:04
- Zuletzt bearbeitet 21.11.2024 09:31:24
Sylius is an Open Source eCommerce Framework on Symfony. A security vulnerability was discovered in the `/api/v2/shop/adjustments/{id}` endpoint, which retrieves order adjustments based on incremental integer IDs. The vulnerability allows an attacker...
CVE-2024-34349
- EPSS 0.07%
- Veröffentlicht 14.05.2024 15:38:41
- Zuletzt bearbeitet 21.11.2024 09:18:28
Sylius is an open source eCommerce platform. Prior to 1.12.16 and 1.13.1, there is a possibility to execute javascript code in the Admin panel. In order to perform an XSS attack input a script into Name field in which of the resources: Taxons, Produc...
CVE-2024-29376
- EPSS 0.11%
- Veröffentlicht 22.04.2024 19:15:46
- Zuletzt bearbeitet 15.09.2025 15:50:07
Sylius 1.12.13 is vulnerable to Cross Site Scripting (XSS) via the "Province" field in Address Book.
CVE-2022-24749
- EPSS 0.31%
- Veröffentlicht 14.03.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:51:00
Sylius is an open source eCommerce platform. In versions prior to 1.9.10, 1.10.11, and 1.11.2, it is possible to upload an SVG file containing cross-site scripting (XSS) code in the admin panel. In order to perform a XSS attack, the file itself has t...
CVE-2022-24743
- EPSS 0.22%
- Veröffentlicht 14.03.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:59
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing tok...
CVE-2022-24742
- EPSS 0.35%
- Veröffentlicht 14.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:59
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is av...
CVE-2022-24733
- EPSS 0.29%
- Veröffentlicht 14.03.2022 19:15:12
- Zuletzt bearbeitet 21.11.2024 06:50:58
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page...
CVE-2021-32720
- EPSS 0.22%
- Veröffentlicht 28.06.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:07:35
Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, order number, items total, and token value) of all placed orders were exposed to unauthorized users. I...