Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.7epss 0.2%
probabilidade de exploração
0.2%top 93% das CVEs
exploração observada
nãonenhuma fonte reporta
Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Sylius · SyliusReferências
https://github.com/Sylius/Syliushttps://github.com/Sylius/Sylius/commit/9e9aeaacbc97b1fc01d573e44d6679194527905dhttps://github.com/Sylius/Sylius/pull/19216https://github.com/Sylius/Sylius/releases/tag/v2.2.9https://github.com/Sylius/Sylius/security/advisories/GHSA-vv4h-q2x8-74g4https://www.vulncheck.com/advisories/sylius-2-x-before-2.1.16-and-2.2.9-payment-amount-overwrite