sylius/sylius is vulnerable to Improper Verification of Data Authenticity
75
High Risk
OrderPaymentProcessor rewrites the last payment's amount and currency to the order's current total on every cart recalculation, without checking whether that payment has already been handed to a gateway. A customer can pay a legitimate amount through an asynchronous gateway and then change the order total, so the in-flight payment is rewritten to the inflated total and the order is marked fully paid. OrderPaymentsRemover can likewise drop a payment already claimed by a gateway. The fix skips rewriting or removing payments that a gateway has already claimed.
You are affected if you are using a version that falls within the vulnerable range and you use an asynchronous payment gateway that starts transactions through Payment Requests.
sylius/sylius is vulnerable to Improper Verification of Data Authenticity in versions 2.0.0 - 2.1.15 and 2.2.0 - 2.2.8.
Upgrade the sylius/sylius library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.