Arbitrary File Upload Affecting sylius/sylius package, versions <1.9.10>=1.10.0, <1.10.11>=1.11.0, <1.11.2


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
1.11% (63rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-SYLIUSSYLIUS-2423389
  • published15 Mar 2022
  • disclosed15 Mar 2022
  • creditUnknown

Introduced: 15 Mar 2022

CVE-2022-24749  (opens in a new tab)
CWE-434  (opens in a new tab)
CWE-80  (opens in a new tab)

How to fix?

Upgrade sylius/sylius to version 1.9.10, 1.10.11, 1.11.2 or higher.

Overview

sylius/sylius is a platform for PHP, based on Symfony framework.

Affected versions of this package are vulnerable to Arbitrary File Upload by making it possible to upload an SVG file that contains a malicious payload in the admin panel, which may result in a Cross-site Scripting (XSS) attack. In order to perform the attack, the file itself has to be open in a new card or loaded outside of the IMG tag.

Workaround

Require a library that adds on-upload file sanitization and overwrites the service before writing the file to the filesystem.

CVSS Base Scores

version 3.1