Impact
Sylius, an open source eCommerce framework built on Symfony, contains an improper workflow enforcement flaw in its cart FormComponent. When an order is completed but the cart page remains open, the stale LiveComponent does not detect the order’s changed state and continues to allow cart actions. This flaw permits an authenticated customer to modify or permanently delete an already completed order, directly compromising order integrity and potentially affecting financial records.
Affected Systems
Affected versions include Sylius 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5. Versions 2.0.18, 2.1.15, and 2.2.6 contain the patch that resolves the issue.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity, and the EPSS score is not available to gauge current exploitation likelihood. It is not listed in the CISA KEV catalog. The likely attack vector is through legitimate user interaction within the storefront after an order has been finalized; an authenticated customer can perform the exploit by accessing the cart page and invoking the stale LiveComponent actions. An attacker who has authenticated access can thereby alter or delete order data, potentially leading to financial loss or data integrity violations.
OpenCVE Enrichment
Github GHSA