CVE-2022-24752 Information
Description
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2 values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took steps to remediate the vulnerability. The issue is fixed in versions 1.10.1 and 1.11-rc2. As a workaround overwrite theSylius\Component\Grid\Sorting\Sorter.php class and register it in the container. More information about this workaround is available in the GitHub Security Advisory.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.11.0-RC.2 https://github.com/Sylius/SyliusGridBundle/security/advisories/GHSA-2xmm-g482-4439 https://github.com/Sylius/SyliusGridBundle/pull/222 https://github.com/Sylius/SyliusGridBundle/commit/73d0791d0575f955e830a3da4c3345f420d2f784 https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.10.1
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: