Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sylius versions before 2.1.16 and 2.2.9 fail to validate payment amounts during cart recalculation, allowing unauthenticated attackers to modify order totals after gateway transaction initiation. Attackers can pay a small amount, enlarge the order after gateway capture, and have the system mark the inflated order as fully paid while the gateway captured only the original amount. | |
| Title | Sylius 2.x before 2.1.16 and 2.2.9 Payment Amount Overwrite | |
| First Time appeared |
Sylius
Sylius sylius |
|
| Weaknesses | CWE-345 | |
| CPEs | cpe:2.3:a:sylius:sylius:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Sylius
Sylius sylius |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T14:29:46.185Z
Reserved: 2026-09-27T00:20:54.408Z
Link: CVE-2026-100872
No data.
Status : Received
Published: 2026-09-27T13:16:38.523
Modified: 2026-09-27T13:16:38.523
Link: CVE-2026-100872
No data.
OpenCVE Enrichment
No data.
-
CWE-345
Insufficient Verification of Data Authenticity