THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x83g-979r-f5fh (medium) — Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII

[GHSA] GHSA-x83g-979r-f5fh (medium) — Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII

medgithub_advisoriesPublished 2026-07-31

GHSA-x83g-979r-f5fh Severity: medium CVE: CVE-2026-68501

Sylius Mollie Plugin has unauthenticated IDOR that leaks order token and customer PII

### Impact Two unauthenticated Mollie shop endpoints look up orders by a sequential integer `orderId` with no ownership or session check. Chained, they expose customer PII.

`GET /{_locale}/thank-you` (`PageRedirectController::thankYouAction`, route `syli

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x83g-979r-f5fh