← Back

CVE-2026-31825

nvd nist
Published: Mar 10, 2026Modified: Mar 18, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Sylius is an Open Source eCommerce Framework on Symfony. Sylius API filters ProductPriceOrderFilter and TranslationOrderNameAndLocaleFilter pass user-supplied order direction values directly to Doctrine's orderBy() without validation. An attacker can inject arbitrary DQL. The issue is fixed in versions: 1.9.12, 1.10.16, 1.11.17, 1.12.23, 1.13.15, 1.14.18, 2.0.16, 2.1.12, 2.2.3 and above.

Affected (9)

Products: Sylius: Sylius
1 product
Sylius
Configuration A
9 vulnerable
Vulnerable SoftwareAffected Versions
Sylius
Before 1.9.12
From 1.10.0 to 1.10.16
From 1.11.0 to 1.11.17
From 1.12.0 to 1.12.23
From 1.13.0 to 1.13.15
From 1.14.0 to 1.14.18
From 2.0.0 to 2.0.16
From 2.1.0 to 2.1.12
From 2.2.0 to 2.2.3

References (1)

Source: security-advisories@github.com
MitigationVendor Advisory

Timeline

No history available yet.