
We found results for “”
CVE-2022-24733
Good to know:

Date: March 14, 2022
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target application's interface with a different interface provided by the attacker. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. Every response from app should have an X-Frame-Options header set to: "sameorigin". To achieve that, add a new "subscriber" in the app.
Language: PHP
Severity Score
Related Resources (7)
Severity Score
Weakness Type (CWE)
Improper Restriction of Rendered UI Layers or Frames
CWE-1021Top Fix

Upgrade Version
Upgrade to version sylius/sylius - 1.7.0.1;sylius/sylius - dev-dependabot/npm_and_yarn/url-parse-1.5.1;sylius/sylius - 1.9.x-dev;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.10;sylius/sylius - dev-dependabot/composer/psalm/plugin-mockery-0.11.0;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.2.3;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.8;sylius/sylius - 1.2.x-dev;sylius/sylius - dev-dependabot/composer/psalm/plugin-mockery-0.7.0;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.1;sylius/sylius - dev-dependabot/composer/rector/rector-tw-0.17.0;sylius/sylius - 1.3.x-dev;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.2.1;sylius/sylius - dev-dependabot/composer/psalm/plugin-mockery-0.9.1;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.2;sylius/sylius - dev-dependabot/npm_and_yarn/ini-1.3.7;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.2.6;sylius/sylius - v1.9.10;sylius/sylius - dev-dependabot/npm_and_yarn/color-string-1.5.5;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.2.5;sylius/sylius - 1.4.x-dev;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.9;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.2.2;sylius/sylius - dev-dependabot/composer/rector/rector-tw-0.15.10;sylius/sylius - dev-dependabot/composer/rector/rector-tw-0.18.0;sylius/sylius - 1.1.x-dev;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-doctrine-1.3.18;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.5;sylius/sylius - 1.0.x-dev;sylius/sylius - 1.6.x-dev;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-doctrine-1.3.4;sylius/sylius - dev-dependabot/npm_and_yarn/decode-uri-component-0.2.2;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-doctrine-0.12.26;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.6;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.4;sylius/sylius - dev-dependabot/npm_and_yarn/url-parse-1.5.10;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.0.5;sylius/sylius - dev-dependabot/composer/rector/rector-tw-1.1.1;sylius/sylius - 1.5.x-dev;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.7.12;sylius/sylius - dev-dependabot/npm_and_yarn/url-parse-1.5.3;sylius/sylius - dev-dependabot/composer/phpstan/phpstan-1.8.7;sylius/sylius - dev-dependabot/composer/knplabs/gaufrette-tw-0.9;sylius/sylius - 1.7.x-dev;sylius/sylius - dev-dependabot/composer/phparkitect/phparkitect-tw-0.4;sylius/sylius - 1.8.x-dev;sylius/sylius - dev-dependabot/npm_and_yarn/path-parse-1.0.7;sylius/sylius - dev-dependabot/npm_and_yarn/url-parse-1.5.7;sylius/sylius - dev-dependabot/composer/symfonycasts/dynamic-forms-v0.1.2
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | CHANGED |
Confidentiality (C): | LOW |
Integrity (I): | LOW |
Availability (A): | NONE |
CVSS v2
Base Score: |
|
---|---|
Access Vector (AV): | NETWORK |
Access Complexity (AC): | MEDIUM |
Authentication (AU): | NONE |
Confidentiality (C): | PARTIAL |
Integrity (I): | PARTIAL |
Availability (A): | NONE |
Additional information: |