Unauthenticated IDOR in Mollie Sylius Plugin Leaking Customer PII and Order Tokens
Security AdvisoryHighSylius
Affected:
- Sylius/MolliePlugin <=2.2.0
- Sylius/MolliePlugin <2.2.8
- Sylius/MolliePlugin >=3.2.0 <3.2.4
- Sylius/MolliePlugin >=3.3.0 <3.3.1
Fixed in:
- 2.2.8
- 3.2.4
- 3.3.1
Referenced CVEs: CVE-2026-68501 · 6.5
文章内图片已隐藏以节省流量 · Upgrade to Pro to view images & offline archive
This content was auto-fetched from github.com, cleaned by our LLM pipeline, and translated to English. View original.