sylius/sylius is vulnerable to Improper Authorization
65
Medium Risk
The Shop API endpoint that submits Payment Request actions accepts any action value the caller supplies and passes it to the configured gateway. A shop customer who owns an order can request privileged gateway operations such as refund, cancel, or payout that should never be reachable from the shop context. On gateways that expose these actions this lets a customer trigger a refund while the order stays marked paid. The fix validates the requested action against an allowlist of capture, authorize, status, and notify.
You are affected if you are using a version that falls within the vulnerable range and you use the Shop API with a payment gateway that exposes refund, cancel, or payout actions.
sylius/sylius is vulnerable to Improper Authorization in versions 2.0.0 - 2.1.15 and 2.2.0 - 2.2.8.
Upgrade the sylius/sylius library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.