sylius/sylius Security Advisories for v1.10.1 (5)
-
[MEDIUM] Sylius Cross Site Scripting (XSS) vulnerability
PKSA-nsc4-mbdg-1r18 CVE-2024-29376 GHSA-mw82-6m2g-qh6c
Affected version: <=1.12.13
Reported by:
GitHub -
[MEDIUM] Improper sanitize of SVG files during content upload ('Cross-site Scripting') in sylius/sylius
PKSA-bdq8-12rq-1jxx CVE-2022-24749 GHSA-4qrp-27r3-66fj
Affected version: >=1.11.0,<1.11.2|>=1.10.0,<1.10.11|<1.9.10
Reported by:
GitHub -
[HIGH] Insufficient Session Expiration in Sylius
PKSA-xgmg-3j55-68k8 CVE-2022-24743 GHSA-mf3v-f2qq-pf9g
Affected version: >=1.11.0,<1.11.2|>=1.10.0,<1.10.11
Reported by:
GitHub -
[MEDIUM] Sensitive Information Exposure in Sylius
PKSA-4y6p-d93g-pxdh CVE-2022-24742 GHSA-7563-75j9-6h5p
Affected version: >=1.11,<1.11.2|>=1.10,<1.10.11|<1.9.10
Reported by:
GitHub -
[MEDIUM] Improper Restriction of Rendered UI Layers or Frames in Sylius
PKSA-ftgj-pjx7-dswf CVE-2022-24733 GHSA-4jp3-q2qm-9fmw
Affected version: >=1.11.0,<1.11.2|>=1.10.0,<1.10.11|<1.9.10
Reported by:
GitHub