Description


Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, any other user can view the data if browser tab remains unclosed after log out. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. The application must strictly redirect to login page even browser back button is pressed. Another possibility is to set more strict cache policies for restricted content.

Related CPE's


a

sylius

sylius

3

Weaknesses



CWE-200


CWE-668

CVSS impact metrics


CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N

5 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-03-14T19:15:08.683Z

4 years ago

Last modified

2024-11-21T05:50:59.840Z

1 year ago