CVE-2022-24742

MEDIUM

Sylius <1.9.10, <1.10.11, <1.11.2 - Info Disclosure

Title source: llm

Description

Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.

Scores

CVSS v3 5.0
EPSS 0.0035
EPSS Percentile 57.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

Classification

CWE
CWE-200 CWE-668
Status published

Affected Products (2)

sylius/sylius < 1.9.10
sylius/sylius < 1.9.10Packagist

Timeline

Published Mar 14, 2022
Tracked Since Feb 18, 2026