CVE-2022-24733: Improper Restriction of Rendered UI Layers or Frames in Sylius
Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target application's interface with a different interface provided by the attacker. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. Every response from app should have an X-Frame-Options header set to: sameorigin. To achieve that, add a new subscriber in the app.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-24733?
CVE-2022-24733 is a vulnerability in the Sylius eCommerce platform that allows an attacker to perform clickjacking attacks.
What is the severity of CVE-2022-24733?
CVE-2022-24733 has a medium severity with a CVSS score of 6.1.
How does CVE-2022-24733 affect Sylius?
CVE-2022-24733 affects Sylius versions 1.9.10, 1.10.0 to 1.10.11, and 1.11.0 to 1.11.2.
How can an attacker exploit CVE-2022-24733?
An attacker can exploit CVE-2022-24733 by loading the Sylius website within an iframe on a malicious page, enabling a clickjacking attack.
How can I fix CVE-2022-24733?
To fix CVE-2022-24733, upgrade to Sylius versions 1.9.10, 1.10.11, or 1.11.2, which have addressed the vulnerability.