Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:22449
HistoryFeb 03, 2020 - 1:16 p.m.

Unauthorized Channel Switching

2020-02-0313:16:05
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
11

EPSS

0.001

Percentile

19.4%

Sylius is vulnerable to unauthorised channel switching. The vulnerability exists even when kernel.debug is not set to true, the channels can be switched by providing the _channel_code GET parameter in production environments.

EPSS

0.001

Percentile

19.4%

Related for VERACODE:22449