CVE-2026-68501 | Sylius MolliePlugin up to 2.2.7/3.2.3/3.3.0 PageRedirectController/QrCodeAction fetchQrCodeFromOrder orderId/tokenValue redirect
A vulnerability was found in Sylius MolliePlugin up to 2.2.7/3.2.3/3.3.0. It has been rated as problematic. The affected element is the function PageRedirectController::thankYouAction/QrCodeAction::fetchQrCodeFromOrder of the component PageRedirectController/QrCodeAction. Performing a manipulation of the argument orderId/tokenValue results in open redirect.
This vulnerability is identified as CVE-2026-68501. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.VulDB Recent EntriesRead More