在 Sylius 1.12.25 之前、1.13.17 之前、1.14.20 之前、2.1.16 之前以及 2.2.9 之前的版本中,由独立的后台管理 API(Admin API)和商店 API(Shop API)端点签发的 JWT 令牌中未包含防火墙(firewall)标识信息。攻击者可以使用管理员的电子邮件地址注册一个商店客户账户,并获取一个令牌,该令牌在后台管理 API 中被解析为该管理员的身份,从而授予攻击者完整的后台管理权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100870 | 8.8 HIGH | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning |
| CVE-2026-100872 | 7.5 HIGH | Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite |
| CVE-2026-100869 | 5.9 MEDIUM | Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API |
No comments yet