CVE-2021-41120: Unauthorized access to Credit card form in sylius/paypal-plugin

Published Oct 5, 2021
·
Updated

sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL to the payment page done after checkout was created with autoincremented payment id (/pay-with-paypal/{id}) and therefore it was easy to predict. The problem is that the Credit card form has prefilled "credit card holder" field with the Customer's first and last name and hence this can lead to personally identifiable information exposure. Additionally, the mentioned form did not require authentication. The problem has been patched in Sylius/PayPalPlugin 1.2.4 and 1.3.1. If users are unable to update they can override a syliuspaypalpluginpaywithpaypalform route and change its URL parameters to (for example) {orderToken}/{paymentId}, then override the Sylius\PayPalPlugin\Controller\PayWithPayPalFormAction service, to operate on the payment taken from the repository by these 2 values. It would also require usage of custom repository method. Additionally, one could override the @SyliusPayPalPlugin/payWithPaypal.html.twig template, to add contingencies: ['SCAALWAYS'] line in hostedFields.submit(...) function call (line 421). It would then have to be handled in the function callback.

Affected Software

2 affected components
Sylius Paypal Sylius>=1.0.0<1.2.4
Sylius Paypal Sylius>=1.3.0<1.3.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Sylius/PayPalPlugin to a version that resolves this vulnerability.

    Fixed in 1.2.4
  2. Upgrade

    Upgrade Sylius/PayPalPlugin to a version that resolves this vulnerability.

    Fixed in 1.3.1
  3. Configuration

    In the hostedFields.submit(...) function call (line 421), add the contingencies: ['SCA_ALWAYS'] line as described.

    SyliusPayPalPlugin/payWithPaypal.html.twig contingencies (SCA_ALWAYS) = ['SCA_ALWAYS']
  4. Configuration

    If users cannot update, override the sylius_paypal_plugin_pay_with_paypal_form route to use URL parameters in the format {orderToken}/{paymentId} (instead of an autoincremented {id}). Then override the Sylius\PayPalPlugin\Controller\PayWithPayPalFormAction service to operate on the payment taken from the repository by these 2 values, and ensure it is handled in the function callback.

    Sylius PayPal plugin route / controller service override pay-with-paypal URL parameters = {orderToken}/{paymentId}
  5. Compensating control

    For the Credit card form issue, ensure the 'credit card holder' prefilled value does not expose the Customer's first and last name (prefilled personally identifiable information).

Event History

Oct 5, 2021
CVE Published
via MITRE·08:35 PM
Data Sourced
via MITRE·08:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
RemedyDescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is CVE-2021-41120?

CVE-2021-41120 is a vulnerability in the Sylius Paypal plugin that allows for easy prediction of the payment page URL after checkout, making it susceptible to potential attacks.

2

What is the severity of CVE-2021-41120?

CVE-2021-41120 has a severity keyword of 'high' and a severity value of 7.5.

3

Which versions of the Sylius Paypal plugin are affected by CVE-2021-41120?

Versions 1.0.0 to 1.2.4 and versions 1.3.0 to 1.3.1 of the Sylius Paypal plugin are affected by CVE-2021-41120.

4

How can an attacker exploit CVE-2021-41120?

An attacker can exploit CVE-2021-41120 by easily predicting the URL to the payment page after checkout, potentially gaining access to sensitive information entered in the credit card form.

5

How can CVE-2021-41120 be mitigated?

To mitigate CVE-2021-41120, it is recommended to update the Sylius Paypal plugin to a version that is not affected by the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203