GHSA-2hp7-mfr2-4fg8HighCVSS 7.5

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart...

Published
September 27, 2026
Last Modified
September 27, 2026

🔗 CVE IDs covered (1)

📋 Description

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.

🔗 References (8)