Impact
The vulnerability in the shop account API endpoint does not check whether a payment method chosen by a customer belongs to the channel associated with the order. An authenticated user, having placed an order that is still in the "STATE_NEW" status, can therefore assign any globally enabled payment method, even those excluded from that channel by the store operator. This allows the customer to override channel‑specific payment restrictions, potentially leading to fraudulent transaction processing or violating business rules.
Affected Systems
Sylius eCommerce Framework (Sylius) versions starting with 2.0.0 and earlier than 2.0.18, 2.1.15, and 2.2.6 are affected. The issue is fixed in those specified release thresholds and subsequently.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is considered low‑to‑moderate severity. The EPSS score is not available and it is not listed in the CISA KEV catalog. Exploitation requires an authenticated customer account and an order that has not yet been paid; the attack does not grant code execution or elevated privileges beyond those of the user, but it does provide a mechanism to bypass operator‑defined payment method constraints.
OpenCVE Enrichment
Github GHSA