CVE-2021-41120: Unauthorized access to Credit card form in sylius/paypal-plugin
sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy to predict. The problem is that the Credit card form has prefilled "credit card holder" field with the Customer's first and last name and hence this can lead to personally identifiable information exposure. Additionally, the mentioned form did not require authentication. The problem has been patched in Sylius/PayPalPlugin 1.2.4 and 1.3.1. If users are unable to update they can override a syliuspaypalpluginpaywithpaypalform route and change its URL parameters to (for example) {orderToken}/{paymentId}, then override the Sylius\PayPalPlugin\Controller\PayWithPayPalFormAction service, to operate on the payment taken from the repository by these 2 values. It would also require usage of custom repository method. Additionally, one could override the @SyliusPayPalPlugin/payWithPaypal.html.twig template, to add contingencies: ['SCAALWAYS'] line in hostedFields.submit(...) function call (line 421). It would then have to be handled in the function callback.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Sylius/PayPalPluginto a version that resolves this vulnerability.Fixed in 1.2.4 - Upgrade
Upgrade
Sylius/PayPalPluginto a version that resolves this vulnerability.Fixed in 1.3.1 - Configuration
In the hostedFields.submit(...) function call (line 421), add the contingencies: ['SCA_ALWAYS'] line as described.
SyliusPayPalPlugin/payWithPaypal.html.twig contingencies (SCA_ALWAYS) = ['SCA_ALWAYS'] - Configuration
If users cannot update, override the sylius_paypal_plugin_pay_with_paypal_form route to use URL parameters in the format {orderToken}/{paymentId} (instead of an autoincremented {id}). Then override the Sylius\PayPalPlugin\Controller\PayWithPayPalFormAction service to operate on the payment taken from the repository by these 2 values, and ensure it is handled in the function callback.
Sylius PayPal plugin route / controller service override pay-with-paypal URL parameters = {orderToken}/{paymentId} - Compensating control
For the Credit card form issue, ensure the 'credit card holder' prefilled value does not expose the Customer's first and last name (prefilled personally identifiable information).
Event History
Frequently Asked Questions
What is CVE-2021-41120?
CVE-2021-41120 is a vulnerability in the Sylius Paypal plugin that allows for easy prediction of the payment page URL after checkout, making it susceptible to potential attacks.
What is the severity of CVE-2021-41120?
CVE-2021-41120 has a severity keyword of 'high' and a severity value of 7.5.
Which versions of the Sylius Paypal plugin are affected by CVE-2021-41120?
Versions 1.0.0 to 1.2.4 and versions 1.3.0 to 1.3.1 of the Sylius Paypal plugin are affected by CVE-2021-41120.
How can an attacker exploit CVE-2021-41120?
An attacker can exploit CVE-2021-41120 by easily predicting the URL to the payment page after checkout, potentially gaining access to sensitive information entered in the credit card form.
How can CVE-2021-41120 be mitigated?
To mitigate CVE-2021-41120, it is recommended to update the Sylius Paypal plugin to a version that is not affected by the vulnerability.