top of page
perceptive_background_267k.jpg

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's POST /{_locale}/updat…

Published:

29 juli 2026 om 22:00:00

Alert date:

30 juli 2026 om 22:03:35

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

A critical vulnerability exists in the Sylius Mollie Plugin prior to versions 2.2.8, 3.2.4, and 3.3.1. The POST /{_locale}/update-payment webhook endpoint accepts attacker-controlled 'id' and 'orderId' parameters without verifying that the Mollie payment belongs to the referenced Sylius order. An unauthenticated attacker with any valid paid Mollie payment ID can mark a victim's order as paid without actually transferring funds. This is essentially a payment bypass vulnerability allowing fraudulent order completion. The flaw stems from insufficient validation of the relationship between payment IDs and order IDs in the webhook handler. Fixes have been released in versions 2.2.8, 3.2.4, and 3.3.1 of the plugin. Three separate commits and pull requests were issued to address the vulnerability across the affected version branches.

Technical details

Mitigation steps:

Affected products:

Sylius Mollie Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page