Information Exposure Through an Error Message in Sylius - CVE-2019-16768
Published: December 5, 2019 / Updated: April 27, 2026
Sylius
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper handling of exception messages in the login action when processing login attempts that trigger internal exceptions. A remote user can submit crafted login requests to disclose sensitive information.
Internal exception details may be presented to the user through a validation message on the shop login page.