Executive brief
Sylius, an e-commerce platform, contains a security flaw in its payment request system. An attacker who obtains a specific payment link can view sensitive customer order details (including email and addresses) or redirect future payments to a malicious website. This could lead to the theft of customer data or financial fraud by intercepting buyer payments.
Technical details
An Insecure Direct Object Reference (IDOR) exists in the GET, PUT, and POST endpoints for payment requests in Sylius. The application fails to verify if the authenticated user or guest session owns the order associated with a payment request hash or token. By obtaining a payment request UUID, an attacker can retrieve the underlying order's tokenValue, granting access to full order details including customer PII. Additionally, attackers can modify 'target_path' and 'after_path' fields to redirect users to malicious URLs during the payment flow. The issue is fixed in versions 2.0.18, 2.1.15, and 2.2.6.
Affected products
- Sylius Sylius/Sylius >= 2.0.0, < 2.0.18
- Sylius Sylius/Sylius >= 2.1.0, < 2.1.15
- Sylius Sylius/Sylius >= 2.2.0, < 2.2.6
Timeline
- 2026-06-02: disclosed: Initial publication date
- 2026-07-09: advisory: Last updated date