Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.2%
exploitation probability
0.2%top 93% of all CVEs
observed exploitation
nono source reports it
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Affected products
Sylius · SyliusReferences
https://github.com/Sylius/Syliushttps://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905dhttps://github.com/Sylius/Sylius/pull/19216https://github.com/Sylius/Sylius/releases/tag/v2.2.9https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-payment-amount-overwrite