THREAT OPS › Threat News › [GHSA] GHSA-x83g-979r-f5fh (medium) — Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
[GHSA] GHSA-x83g-979r-f5fh (medium) — Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
GHSA-x83g-979r-f5fh Severity: medium CVE: CVE-2026-68501
Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII
### Impact Two unauthenticated Mollie shop endpoints look up orders by a sequential integer `orderId` with no ownership or session check. Chained, they expose customer PII.
`GET /{_locale}/thank-you` (`PageRedirectController::thankYouAction`, route `syli
Indicators of compromise
- CVE-2026-68501cve
Original source: https://github.com/advisories/GHSA-x83g-979r-f5fh