Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-1308 | Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target application's interface with a different interface provided by the attacker. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. Every response from app should have an X-Frame-Options header set to: ``sameorigin``. To achieve that, add a new `subscriber` in the app. |
Github GHSA |
GHSA-4jp3-q2qm-9fmw | Improper Restriction of Rendered UI Layers or Frames in Sylius |
Wed, 23 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T18:54:19.052Z
Reserved: 2022-02-10T00:00:00.000Z
Link: CVE-2022-24733
Updated: 2024-08-03T04:20:49.808Z
Status : Modified
Published: 2022-03-14T19:15:12.173
Modified: 2024-11-21T06:50:58.550
Link: CVE-2022-24733
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA