Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 8.7epss 0.2%
probabilidad de explotación
0.2%top 93% de las CVE
explotación observada
noninguna fuente lo reporta
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Productos afectados
Sylius · SyliusReferencias
https://github.com/Sylius/Syliushttps://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905dhttps://github.com/Sylius/Sylius/pull/19216https://github.com/Sylius/Sylius/releases/tag/v2.2.9https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-payment-amount-overwrite