CVE-2022-24743 affects Sylius, an open-source eCommerce platform, where a flaw in password reset functionality allowed the same token to be reused multiple times, potentially leading to unauthorized password changes. This vulnerability carries a high CVSS score of 8.2, indicating a critical risk due to its network-based attack vector, low complexity, and high impact on integrity. While no active exploitation, public exploit code, or significant community discussion has been observed, the issue is fixed in Sylius versions 1.10.11 and 1.11.2, with a workaround also available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.10.0, < 1.10.11CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | ||
>= 1.11.0, < 1.11.2CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.