8.2
CVE-2026-100869
- EPSS 0.26%
- Veröffentlicht 27.09.2026 13:16:38
- Zuletzt bearbeitet 28.09.2026 20:57:50
- Erkennungen
Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API
Sylius versions before 2.1.16 and 2.2.9 fail to restrict payment request actions in the Shop API endpoint, allowing customers to trigger refunds on completed orders. Attackers with order tokens can submit arbitrary payment actions like refunds that payment gateways execute while Sylius maintains order as paid, causing financial loss.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSylius
≫
Produkt
Sylius
Default Statusunaffected
Version
2.0.0
Version <
2.1.16
Status
affected
Version
2.2.0
Version <
2.2.9
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.163 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.2 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 5.9 | 2.2 | 3.6 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
https://github.com/Sylius/Sylius
https://github.com/Sylius/Sylius/commit/5813831f60f3a60b735a86a57c4b519626a3b75d
https://github.com/Sylius/Sylius/pull/19214
https://github.com/Sylius/Sylius/releases/tag/v2.2.9
https://github.com/Sylius/Sylius/security/advisories/GHSA-2rv4-pjmm-7fxf
https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-arbitrary-payment-action-via-shop-api