{"id":"CVE-2022-24733","aliases":["GHSA-4jp3-q2qm-9fmw"],"url":"https://o3.security/vulnerability/CVE-2022-24733","summary":"Improper Restriction of Rendered UI Layers or Frames in Sylius","details":"Sylius is an open source eCommerce platform. Prior to versions 1.9.10, 1.10.11, and 1.11.2, it is possible for a page controlled by an attacker to load the website within an iframe. This will enable a clickjacking attack, in which the attacker's page overlays the target application's interface with a different interface provided by the attacker. The issue is fixed in versions 1.9.10, 1.10.11, and 1.11.2. A workaround is available. Every response from app should have an X-Frame-Options header set to: ``sameorigin``. To achieve that, add a new `subscriber` in the app.","published":"2022-03-14T18:50:10Z","modified":"2026-08-12T03:51:43.956870228Z","cvss":{"score":6.1,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"},"epss":{"score":0.00907,"percentile":0.56713,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"sylius/sylius","fixedVersion":"1.9.10"},{"ecosystem":"Packagist","name":"sylius/sylius","fixedVersion":"1.10.11"},{"ecosystem":"Packagist","name":"sylius/sylius","fixedVersion":"1.11.2"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/Sylius/Sylius/releases/tag/v1.10.11"},{"type":"WEB","url":"https://github.com/Sylius/Sylius/releases/tag/v1.11.2"},{"type":"WEB","url":"https://github.com/Sylius/Sylius/releases/tag/v1.9.10"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24733.json"},{"type":"ADVISORY","url":"https://github.com/Sylius/Sylius/security/advisories/GHSA-4jp3-q2qm-9fmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24733"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:43.956870228Z"}}