Sylius 在 2.1.16 及 2.2.9 之前的版本中存在一个缺陷,未能正确限制商店 API 端点中的支付请求操作。攻击者可以利用此漏洞,在订单已完成的情况下触发退款操作。由于攻击者持有有效的订单令牌,他们可以提交任意的支付操作(例如退款),支付网关会执行这些操作,但 Sylius 仍会将订单状态保持为“已支付”。这种行为可能导致用户遭受财务损失。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100871 | 8.8 HIGH | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows A |
| CVE-2026-100870 | 8.8 HIGH | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning |
| CVE-2026-100872 | 7.5 HIGH | Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite |
No comments yet