Impact
Sylius 2.x before 2.1.16 and 2.2.9 does not enforce strict checks on payment request actions through its Shop API endpoint. An attacker who obtains a valid order token can craft requests that instruct the payment gateway to issue refunds for orders already marked as paid. The system accepts these requests and passes them to the chosen payment gateway, while Sylius continues to record the order as paid, creating a financial discrepancy and potential loss for the merchant.
Affected Systems
Vendor: Sylius; Product: Sylius e‑commerce platform; Affected versions: all releases prior to 2.1.16 and prior to 2.2.9. The issue is present in Sylius 2.x up through those specific release points.
Risk and Exploitability
The CVSS base score is 8.2, indicating a high severity vulnerability. EPSS data is not available, so the current exploitation probability is uncertain; however, the lack of sufficient authorization checks suggests the attack can be carried out remotely via the exposed Shop API. This feature is not listed in the CISA KEV catalog, but the remote nature and potential for financial loss make it high risk for any e‑commerce installation that exposes the Shop API without additional safeguards.
OpenCVE Enrichment