The Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to versions 2.2.8, 3.2.4, and 3.3.1, the plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints do not perform ownership or session checks when looking up sequential orderId values. This exposes order tokenValue values that c [truncated]
The Sylius Mollie Plugin, used for integrating Mollie payment gateway with Sylius applications, contains a vulnerability. Specifically, the POST /{_locale}/update-payment payment webhook does not verify that the Mollie payment belongs to the referenced Sylius order. This oversight allows an unauthenticated attacker with any valid paid Mollie payment ID to mark a victim order as paid without transferring f [truncated]