CVE-2025-30152 | Sylius PayPalPlugin up to 1.6.1/1.7.1/2.0.1 external control of assumed-immutable web parameter (GHSA-hxg4-65p5-9w37)
A vulnerability classified as problematic has been found in Sylius PayPalPlugin up to 1.6.1/1.7.1/2.0.1. This affects an unknown part. The manipulation leads to external control of assumed-immutable web parameter.
This vulnerability is uniquely identified as CVE-2025-30152. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.