Sylius 2.1.16 及 2.2.9 之前的版本在购物车重新计算过程中未能正确验证支付金额,使得未经身份验证的攻击者能够在支付网关交易发起后篡改订单总额。攻击者可以先支付一小部分金额,然后在支付网关捕获(扣款)后扩大订单金额,而系统会将该被虚增的订单标记为“已全额支付”,尽管支付网关实际仅扣除了原始较小的金额。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100871 | 8.8 HIGH | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 JWT Audience Confusion Allows A |
| CVE-2026-100870 | 8.8 HIGH | Sylius before 1.12.25, 1.13.17, 1.14.20, 2.1.16, and 2.2.9 Admin Password Reset Poisoning |
| CVE-2026-100869 | 5.9 MEDIUM | Sylius 2.x before 2.1.16 and 2.2.9 Arbitrary Payment Action via Shop API |
No comments yet