CVE-2019-16768 affects Sylius versions prior to 1.3.14, 1.4.10, 1.5.7, and 1.6.3, where internal exception messages, such as database errors, are improperly exposed to users through the UI during login attempts. This flaw, categorized as CWE-209 (Information Exposure Through an Error Message), could lead to the leakage of sensitive system information. The vulnerability has a CVSS v3.1 score of 4.3 (Medium), indicating a low-complexity attack that requires low privileges and no user interaction, potentially leading to a low impact on confidentiality. While it has a low EPSS score and FAUCET Risk Score, suggesting a low likelihood of exploitation, it could still expose internal system details. There is no evidence of active exploitation, nor is exploit code available on platforms like Metasploit or ExploitDB. The CVE has garnered no community discussion or media coverage, suggesting a low level of public awareness or interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.14CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | ||
>= 1.4.0, < 1.4.10CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | ||
>= 1.5.0, < 1.5.7CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | ||
>= 1.6.0, < 1.6.3CPE matchmatch criteria | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.