Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x83g-979r-f5fh | Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sylius
Sylius mollieplugin |
|
| Vendors & Products |
Sylius
Sylius mollieplugin |
Fri, 31 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1. | |
| Title | Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T15:59:04.182Z
Reserved: 2026-07-30T16:19:08.081Z
Link: CVE-2026-68501
Updated: 2026-07-31T15:53:29.591Z
Status : Received
Published: 2026-07-30T21:18:13.180
Modified: 2026-07-31T16:17:12.053
Link: CVE-2026-68501
No data.
OpenCVE Enrichment
Updated: 2026-08-02T20:34:38Z
Github GHSA