MEDIUMCVSS 6.5Vulnerability
CVE-2026-68501
Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1.
Properties
- summary
- Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
- severity
- MEDIUM
- epss_score
- 0.00429
- cvss_score
- 6.5
- ghsa_published
- 2026-07-31T16:52:59Z
- source_url
- https://github.com/advisories/GHSA-x83g-979r-f5fh
- ghsa_updated
- 2026-07-31T16:53:01Z
- ghsa_id
- GHSA-x83g-979r-f5fh
- score
- 6.5
- cve_id
- CVE-2026-68501
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- signal_observed_at
- 2026-09-11T17:54:55+00:00
- is_ghsa_only
- false
- vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- published_at
- 2026-07-30T21:18:13.180
- last_modified
- 2026-09-10T20:12:43.783
- epss_percentile
- 0.36326
Related Entities (6)
DESCRIBED_BY (1)
→[Source]NVD
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (1)
←[Software]composer/sylius/mollie-plugin
AFFECTS (1)
→[Software]composer/sylius/mollie-plugin
HAS_WEAKNESS (1)
→[Weakness]Authorization Bypass Through User-Controlled Key
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph