CVE-2022-24743
- EPSS 1.25%
- Veröffentlicht 14.03.2022 21:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:59
Sylius is an open source eCommerce platform. Prior to versions 1.10.11 and 1.11.2, the reset password token was not set to null after the password was changed. The same token could be used several times, which could result in leak of the existing tok...
CVE-2022-24742
- EPSS 0.82%
- Veröffentlicht 14.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 06:50:59
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is av...
CVE-2022-24733
- EPSS 0.91%
- Veröffentlicht 14.03.2022 19:15:12
- Zuletzt bearbeitet 21.11.2024 06:50:58
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page...
CVE-2021-32720
- EPSS 0.88%
- Veröffentlicht 28.06.2021 19:15:11
- Zuletzt bearbeitet 21.11.2024 06:07:35
Sylius is an Open Source eCommerce platform on top of Symfony. In versions of Sylius prior to 1.9.5 and 1.10.0-RC.1, part of the details (order ID, order number, items total, and token value) of all placed orders were exposed to unauthorized users. I...
CVE-2020-15245
- EPSS 0.63%
- Veröffentlicht 19.10.2020 21:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:10
In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, change it to the mail another@domain.com and stay verified and enabled. This may lead to having accounts addressed to totally diff...
CVE-2020-5218
- EPSS 0.6%
- Veröffentlicht 27.01.2020 21:15:11
- Zuletzt bearbeitet 21.11.2024 05:33:42
Affected versions of Sylius give attackers the ability to switch channels via the _channel_code GET parameter in production environments. This was meant to be enabled only when kernel.debug is set to true. However, if no sylius_channel.debug is set e...
CVE-2019-12186
- EPSS 0.55%
- Veröffentlicht 31.12.2019 15:15:10
- Zuletzt bearbeitet 21.11.2024 04:22:23
An issue was discovered in Sylius products. Missing input sanitization in sylius/sylius 1.0.x through 1.0.18, 1.1.x through 1.1.17, 1.2.x through 1.2.16, 1.3.x through 1.3.11, and 1.4.x through 1.4.3 and sylius/grid 1.0.x through 1.0.18, 1.1.x throug...
CVE-2019-16768
- EPSS 0.75%
- Veröffentlicht 05.12.2019 20:15:09
- Zuletzt bearbeitet 21.11.2024 04:31:09
In affected versions of Sylius, exception messages from internal exceptions (like database exception) are wrapped by \Symfony\Component\Security\Core\Exception\AuthenticationServiceException and propagated through the system to UI. Therefore, some in...