Sylius 在 1.12.25、1.13.17、1.14.20、2.1.16 以及 2.2.9 之前的版本中,构建管理员密码重置链接时使用了请求中的 Host 头,且未对其进行任何验证。这使得未经身份验证的攻击者能够将密码重置令牌重定向至其控制的域名。攻击者可以通过伪造 Host 头,对已知管理员邮箱地址发起密码重置请求,从而截获有效的密码重置令牌,并接管管理员账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100871 | 8.8 HIGH | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows A |
| CVE-2026-100872 | 7.5 HIGH | Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite |
| CVE-2026-100869 | 5.9 MEDIUM | Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API |
No comments yet