Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-x83g-979r-f5fh | Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII |
Sun, 02 Aug 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Sylius
Sylius mollieplugin |
|
| Vendors & Products |
Sylius
Sylius mollieplugin |
Fri, 31 Jul 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Jul 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Sylius Mollie Plugin's GET /{_locale}/thank-you PageRedirectController::thankYouAction and GET /{_locale}/get-code QrCodeAction::fetchQrCodeFromOrder endpoints look up sequential orderId values without ownership or session checks, exposing order tokenValue values that can be used with GET /{_locale}/register-after-checkout/{tokenValue} to view customer first name, last name, and email. This issue is fixed in 2.2.8, 3.2.4, and 3.3.1. | |
| Title | Sylius Mollie Plugin: Unauthenticated IDOR leaks order token and customer PII | |
| Weaknesses | CWE-639 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-07-31T15:59:04.182Z
Reserved: 2026-07-30T16:19:08.081Z
Link: CVE-2026-68501
Updated: 2026-07-31T15:53:29.591Z
Status : Received
Published: 2026-07-30T21:18:13.180
Modified: 2026-07-31T16:17:12.053
Link: CVE-2026-68501
No data.
OpenCVE Enrichment
Updated: 2026-08-02T20:34:38Z
Github GHSA