Impact
Sylius versions through 2.3.0 contain an authorization bypass that allows attackers without authentication to read unmoderated and rejected product reviews. The filter that should enforce moderation, the AcceptedExtension, is not applied to the item operation, enabling an attacker to retrieve review titles, ratings, comments, timestamps and author first names. This results in the disclosure of potentially sensitive customer feedback and merchant information. The weakness is categorized as CWE‑639, indicating that user‑controlled conditions are exploited to bypass normal authorization checks.
Affected Systems
The affected vendor and product are Sylius, specifically the Sylius e‑commerce platform. All releases up to and including version 2.3.0 are vulnerable. No specific sub‑components beyond the Shop API Product‑Review endpoint are listed, but the vulnerability resides in the default configuration of the API bundle of Sylius.
Risk and Exploitability
The CVSS score of 6.9 reflects a medium severity vulnerability. Although the EPSS score is not available, the lack of an authentication requirement and the ability to enumerate sequential identifiers on the publicly exposed endpoint suggest that exploitation is feasible over the network. The vulnerability is currently not listed in the CISA KEV catalog, indicating that there is no known mass exploitation campaign. Nonetheless, any attacker who discovers product-review identifiers can obtain a range of data, making a moderate risk assessment appropriate for e‑commerce sites that rely on the default operational settings.
OpenCVE Enrichment