Sylius 是基于 Symfony 的开源电子商务框架。版本 2.0.0 至 2.0.17、2.1.0 至 2.1.14 以及 2.2.0 至 2.2.5 中,购物车的 存在一个不恰当的工作流执行漏洞(Improper Workflow Enforcement)。当订单已完成,但购物车页面仍然保持打开状态时,陈旧的 LiveComponent 无法检测到订单状态的变化,并继续允许对购物车执行操作,这使得已认证的顾客可以修改甚至永久删除一个已经完成的订单。版本 2.0.18、2.1.15 和 2.2.6 已包含修复
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53639 | 6.3 MEDIUM | Sylius: IDOR on Shop Payment Request API endpoints |
| CVE-2026-53638 | 4.3 MEDIUM | Sylius: Channel-based payment method restriction bypass on shop account orders API endpoin |
No comments yet