8.7
CVE-2026-100872
- EPSS 0.18%
- Veröffentlicht 27.09.2026 13:16:38
- Zuletzt bearbeitet 28.09.2026 20:57:50
- Erkennungen
Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerSylius
≫
Produkt
Sylius
Default Statusunaffected
Version
2.0.0
Version <
2.1.16
Status
affected
Version
2.2.0
Version <
2.2.9
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.068 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| disclosure@vulncheck.com | 8.7 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| disclosure@vulncheck.com | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
|
CWE-345 Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
https://github.com/Sylius/Sylius
https://github.com/Sylius/Sylius/releases/tag/v2.2.9
https://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905d
https://github.com/Sylius/Sylius/pull/19216
https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4
https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-payment-amount-overwrite