Impact
Sylius versions prior to 2.1.16 and 2.2.9 contain a weakness that does not validate payment amounts during cart recalculation. This flaw allows an unauthenticated attacker to alter the total order value after a payment gateway transaction has begun. The system may then consider the inflated order fully paid while the gateway only captures the initially submitted amount, potentially leading to significant financial loss.
Affected Systems
The affected products are Sylius e-commerce platform versions 2.x before 2.1.16 and before 2.2.9. Upgrade to Sylius 2.1.16 or later, or 2.2.9 or later, to receive the fix that enforces proper payment amount validation.
Risk and Exploitability
The CVSS score of 8.7 classifies this as a high‑severity vulnerability, and the EPSS score is not available, indicating that at the time of reporting no measurable exploitation probability was logged. The vulnerability is not listed in the CISA KEV catalog. Attackers do not need privileged access to exploit the flaw; the likely attack vector is through unauthenticated requests to the cart recalculation API, allowing malicious alteration of order totals.
OpenCVE Enrichment