CVE-2026-31819 | Sylius up to 2.2.2 impersonateAction/StorageBasedLocaleSwitcher redirect (GHSA-9ffx-f77r-756w)
A vulnerability was found in Sylius up to 2.2.2 and classified as problematic. This issue affects the function CurrencySwitchController::switchAction/ImpersonateUserController::impersonateAction/StorageBasedLocaleSwitcher. Executing a manipulation can lead to open redirect.
This vulnerability is registered as CVE-2026-31819. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.