| Summary | In Sylius before versions 1.6.9, 1.7.9 and 1.8.3, the user may register in a shop by email mail@example.com, verify it, change it to the mail another@domain.com and stay verified and enabled. This may lead to having accounts addressed to totally different emails, that were verified. Note, that this way one is not able to take over any existing account (guest or normal one). The issue has been patched in Sylius 1.6.9, 1.7.9 and 1.8.3. As a workaround, you may resolve this issue on your own by creating a custom event listener, which will listen to the sylius.customer.pre_update event. You can determine that email has been changed if customer email and user username are different. They are synchronized later on. Pay attention, to email changing behavior for administrators. You may need to skip this logic for them. In order to achieve this, you should either check master request path info, if it does not contain /admin prefix or adjust event triggered during customer update in the shop. You can find more information on how to customize the event here. |
|---|---|
| Publication Date | Oct. 20, 2020, 6:15 a.m. |
| Registration Date | Jan. 26, 2021, 11:53 a.m. |
| Last Update | Nov. 21, 2024, 2:05 p.m. |
| CVSS3.1 : MEDIUM | |
| スコア | 4.3 |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃に必要な特権レベル(PR) | 低 |
| 利用者の関与(UI) | 不要 |
| 影響の想定範囲(S) | 変更なし |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | 低 |
| 可用性への影響(A) | なし |
| CVSS2.0 : MEDIUM | |
| Score | 4.0 |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:N/I:P/A:N |
| 攻撃元区分(AV) | ネットワーク |
| 攻撃条件の複雑さ(AC) | 低 |
| 攻撃前の認証要否(Au) | 単一 |
| 機密性への影響(C) | なし |
| 完全性への影響(I) | 低 |
| 可用性への影響(A) | なし |
| Get all privileges. | いいえ |
| Get user privileges | いいえ |
| Get other privileges | いいえ |
| User operation required | いいえ |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | 1.8.0 | 1.8.3 | |||
| cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | 1.7.0 | 1.7.9 | |||
| cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | 1.6.9 | ||||
| Title | Sylius におけるクロスサイトスクリプティングの脆弱性 |
|---|---|
| Summary | Sylius には、クロスサイトスクリプティングの脆弱性が存在します。 |
| Possible impacts | 情報を改ざんされる可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | Oct. 19, 2020, midnight |
| Registration Date | May 21, 2021, 2:41 p.m. |
| Last Update | May 21, 2021, 2:41 p.m. |
| Sylius |
| Sylius 1.6.9 未満 |
| Sylius 1.7.9 未満 |
| Sylius 1.8.3 未満 |
| No | Changed Details | Date of change |
|---|---|---|
| 1 | [2021年05月21日] 掲載 |
May 21, 2021, 2:41 p.m. |