Versio.io

CVE-2022-24752

Common vulnerabilities & exposures (CVE)

CVE databaseCVE database blogpostRelease & EoL database
 
Published at: - 15-03-2022 04:15
Last modified: - 25-03-2022 01:42
Total changes: - 2

Description

SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took steps to remediate the vulnerability. The issue is fixed in versions 1.10.1 and 1.11-rc2. As a workaround, overwrite the`Sylius\Component\Grid\Sorting\Sorter.php` class and register it in the container. More information about this workaround is available in the GitHub Security Advisory.

Common Vulnerability Scoring System (CVSS)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Low
Attack complexity
Network
Attack vector
High
Availability
High
Confidentiality
High
Integrity
None
Privileges required
Unchanged
Scope
None
User interaction
9.8
Base score
3.9
5.9
Exploitability score
Impact score
 

Verification logic

OR
vendor=sylius AND product=syliusgridbundle AND versionEndExcluding=1.10.1
vendor=sylius AND product=syliusgridbundle AND version=1.11.0 AND update=-
vendor=sylius AND product=syliusgridbundle AND version=1.11.0 AND update=alpha1
vendor=sylius AND product=syliusgridbundle AND version=1.11.0 AND update=beta1
vendor=sylius AND product=syliusgridbundle AND version=1.11.0 AND update=rc1
 

Reference

 


Keywords

NVD

 

CVE-2022-24752

 

CVE

 

Common vulnerabilities & exposures

 

CVSS

 

Common vulnerability scoring system

 

Security

 

Vulnerabilities

 

Exposures

 

We use cookies to ensure that we give you the best experience on our website. Read privacy policies for more information.