CVE-2020-15146: Remote Code Execution in SyliusResourceBundle

Published Aug 18, 2020
·
Updated

Impact

Request parameters injected inside an expression evaluated by symfony/expression-language package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution.

The vulnerable versions include: <=1.3.13 || >=1.4.0 <=1.4.6 || >=1.5.0 <=1.5.1 || >=1.6.0 <=1.6.3.

Example

yaml syliusgrid: grids: foo: fields: bar: options: baz: "expr:service('sylius.repository.product').find($id)"

In this case, $id can be prepared in a way that calls other services.

If you visit /route?id="~service('doctrine').getManager().getConnection().executeQuery("DELETE FROM TABLE")~", it will result in a following expression expr:service('repository').find(""~service('doctrine').getManager().getConnection().executeQuery("DELETE FROM TABLE")~""), which will execute a query on the currently connected database.

To find a vulnerability in your application, look for any routing definition that uses request parameters inside expression language.

Patches

This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.

Workarounds

The fix requires adding addslashes in OptionsParser::parseOptionExpression to sanitize user input before evaluating it using the expression language.

php - return isstring($variable) ? sprintf('"%s"', $variable) : $variable; + return isstring($variable) ? sprintf('"%s"', addslashes($variable)) : $variable;

Acknowledgements

This security issue has been reported by Craig Blanchette (@isometriks), thanks a lot!

For more information

If you have any questions or comments about this advisory: Email us at security@sylius.com

Other sources

CVE-2020-15146: Remote Code Execution in OptionsParser while using request parameters inside expression language

In SyliusResourceBundle before versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4, request parameters injected inside an expression evaluated by symfony/expression-language package haven't been sanitized properly. This allows the attacker to access any public service by manipulating that request parameter, allowing for Remote Code Execution. This issue has been patched for versions 1.3.14, 1.4.7, 1.5.2 and 1.6.4. Versions prior to 1.3 were not patched.

Affected Software

9 affected componentsFixes available
composer/sylius/resource-bundle>=1.0.0, <1.1.0, >=1.1.0, <1.2.0, >=1.2.0, <1.3.0, >=1.3.0, <1.3.14, >=1.4.0, <1.4.7, >=1.5.0, <1.5.2, >=1.6.0, <1.6.4
composer/sylius/resource-bundle>=1.0.0<1.3.14
1.3.14
composer/sylius/resource-bundle>=1.6.0<1.6.4
1.6.4
composer/sylius/resource-bundle>=1.5.0<1.5.2
1.5.2
composer/sylius/resource-bundle>=1.4.0<1.4.7
1.4.7
Sylius SyliusResourceBundle<=1.3.13
Sylius SyliusResourceBundle>=1.4.0<=1.4.6
Sylius SyliusResourceBundle>=1.5.0<=1.5.1
Sylius SyliusResourceBundle>=1.6.0<=1.6.3

Event History

Aug 18, 2020
Advisory Published
09:05 AM
Aug 19, 2020
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is CVE-2020-15146?

CVE-2020-15146 is a vulnerability that allows remote code execution in OptionsParser while using request parameters inside express.

2

What is the severity of CVE-2020-15146?

The severity of CVE-2020-15146 is critical, with a CVSS score of 8.8.

3

Which software is affected by CVE-2020-15146?

SyliusResourceBundle versions 1.0.0 to 1.3.14, 1.4.0 to 1.4.7, 1.5.0 to 1.5.2, and 1.6.0 to 1.6.4 are affected by CVE-2020-15146.

4

How can an attacker exploit CVE-2020-15146?

An attacker can exploit CVE-2020-15146 by manipulating a request parameter to access any public service.

5

How can I fix CVE-2020-15146?

To fix CVE-2020-15146, update SyliusResourceBundle to versions 1.3.14, 1.4.7, 1.5.2, or 1.6.4.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203