CVE-2022-24752: SQL Injection through sorting parameters in SyliusGridBundle
SyliusGridBundle is a package of generic data grids for Symfony applications. Prior to versions 1.10.1 and 1.11-rc2, values added at the end of query sorting were passed directly to the database. The maintainers do not know if this could lead to direct SQL injections but took steps to remediate the vulnerability. The issue is fixed in versions 1.10.1 and 1.11-rc2. As a workaround, overwrite theSylius\Component\Grid\Sorting\Sorter.php class and register it in the container. More information about this workaround is available in the GitHub Security Advisory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-24752?
CVE-2022-24752 is a vulnerability in SyliusGridBundle, a package of generic data grids for Symfony applications, that allows for potential direct SQL injections.
What is the severity of CVE-2022-24752?
The severity of CVE-2022-24752 is critical with a CVSS score of 9.8.
Which versions of SyliusGridBundle are affected by CVE-2022-24752?
Versions up to and excluding 1.10.1, 1.11.0, 1.11.0-alpha1, 1.11.0-beta1, and 1.11.0-rc1 of SyliusGridBundle are affected by CVE-2022-24752.
How can I fix CVE-2022-24752?
You should update SyliusGridBundle to version 1.10.1 or apply the necessary patches mentioned in the release notes of the fixed versions.
Where can I find more information about CVE-2022-24752?
You can find more information about CVE-2022-24752 in the references provided: [GitHub Commit](https://github.com/Sylius/SyliusGridBundle/commit/73d0791d0575f955e830a3da4c3345f420d2f784), [GitHub Pull Request](https://github.com/Sylius/SyliusGridBundle/pull/222), [GitHub Release](https://github.com/Sylius/SyliusGridBundle/releases/tag/v1.10.1).