Date
Severity
Critical
Vulnerability
Access Bypass
Affected versions
<7.x-1.7

Description

The Commerce Ingenico module integrates Drupal Commerce with the Ingenico (Ogone) payment gateway and provides a batch process that captures all pending (authorized but uncaptured) transactions.

The module registers the batch capture page with its access callback set to always allow access, so no permission is required. Any user, including anonymous visitors, can reach the form and start the batch that captures every pending transaction against the payment gateway.

This vulnerability is mitigated by the fact that funds are only captured for transactions that are already pending, and the capture must succeed against the configured Ingenico gateway credentials.

Solution

Install the latest version.

If you use the Commerce Ingenico module for Drupal 7, upgrade to Commerce Ingenico 7.x-1.7:


Reported by

Fixed by

  • Tag1 D7ES

Coordinated by

  • Tag1 D7ES