SCA: security update for sylius/paypal-plugin (GHSA-25fx-mxc2-76g7)

high Tenable Cloud Security Plugin ID 408701

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- sylius/paypal-plugin is a paypal plugin for the Sylius development platform. In affected versions the URL
to the payment page done after checkout was created with autoincremented payment id (/pay-with-
paypal/{id}) and therefore it was easy to predict. The problem is that the Credit card form has prefilled
"credit card holder" field with the Customer's first and last name and hence this can lead to personally
identifiable information exposure. Additionally, the mentioned form did not require authentication. The
problem has been patched in Sylius/PayPalPlugin 1.2.4 and 1.3.1. If users are unable to update they can
override a sylius_paypal_plugin_pay_with_paypal_form route and change its URL parameters to (for example)
{orderToken}/{paymentId}, then override the Sylius\PayPalPlugin\Controller\PayWithPayPalFormAction
service, to operate on the payment taken from the repository by these 2 values. It would also require
usage of custom repository method. Additionally, one could override the
@SyliusPayPalPlugin/payWithPaypal.html.twig template, to add contingencies: ['SCA_ALWAYS'] line in
hostedFields.submit(...) function call (line 421). It would then have to be handled in the function
callback. (CVE-2021-41120)

See Also

https://github.com/advisories/GHSA-25fx-mxc2-76g7

Plugin Details

Severity: High

ID: 408701

Version: Revision 1.5

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.18

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2021-41120

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2021

Vulnerability Publication Date: 10/5/2021

Reference Information

CVE: CVE-2021-41120