In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Authorization Bypass Through User-Controlled Key vulnerabilities in an interactive lesson.
Start learningUpgrade sylius/sylius to version 2.0.18, 2.1.15, 2.2.6 or higher.
sylius/sylius is a platform for PHP, based on Symfony framework.
Affected versions of this package are vulnerable to Authorization Bypass Through User-Controlled Key via the GET /api/v2/shop/payment-requests/{hash}, PUT /api/v2/shop/payment-requests/{hash}, and POST /api/v2/shop/orders/{tokenValue}/payment-requests endpoints. An attacker can gain unauthorized access to payment request details and modify payment request payloads by supplying a valid hash or token value obtained through out-of-band methods. This may allow exposure of sensitive order information and manipulation of redirect URLs to attacker-controlled destinations.