CVE-2026-100872 PUBLISHED

Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite

Assigner: VulnCheck
Reserved: 27.09.2026 Published: 27.09.2026 Updated: 27.09.2026

Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Sylius
Product Sylius
Versions Default: unaffected
  • affected from 2.0.0 to 2.1.16 (excl.)
  • affected from 2.2.0 to 2.2.9 (excl.)

Credits

  • leediay153 finder

References

Problem Types

  • Insufficient Verification of Data Authenticity CWE