Improper access control in Sylius - CVE-2021-32720

 

Improper access control in Sylius - CVE-2021-32720

Published: June 28, 2021 / Updated: April 27, 2026


Vulnerability identifier: #VU128210
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-32720
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose order information.

The vulnerability exists due to improper access control in the new API orders endpoint when handling unauthenticated requests for order listings. A remote attacker can send a crafted request to disclose order information.

Exposed data includes order identifiers, order numbers, item totals, and token values, and may also include the number of items in the cart and shipping date details.


Affected software

Sylius

How to mitigate CVE-2021-32720

Install security update from vendor's website.

Sylius - update to 1.9.5

External References

Related Security Bulletins