Impact
Idempotent IDOR flaw allows an attacker who knows a payment request hash to retrieve sensitive order information from Sylius APIs. The GET and PUT payment request endpoints resolve the request solely by the hash, without verifying the requester’s ownership of the linked order. Once the hash is discovered, an attacker can read the payment request and use the exposed payment IRI to retrieve the order’s tokenValue, which grants full access to the order, customer details, and totals. Furthermore, the attacker can modify the payment request payload, changing redirect URLs such as target_path and after_path, enabling phishing or man‑in‑the‑middle attacks. The vulnerability is rooted in improper authorization and is catalogued as CWE‑639.
Affected Systems
Sylius eCommerce Framework is affected. Versions starting with 2.0.0 up to but not including 2.0.18, 2.1.15, and 2.2.6 contain the flaw. Upgrades to 2.0.18 or newer, 2.1.15 or newer, or 2.2.6 or newer resolve the issue.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The exploit requires a valid payment request hash, which is a UUID and must be obtained out‑of‑band (e.g., from logs, shared links, referrer headers, or a co‑located client). Authentication or knowledge of the order token is not required once the hash is known. EPSS is not available, and the vulnerability is currently not listed in CISA KEV. The attack vector is remote and relies on REST API exposure; although obtaining the hash is nontrivial, the low barrier to compromise the order once the hash is known makes the risk moderate.
OpenCVE Enrichment
Github GHSA