Description
The Commerce Ingenico module integrates Drupal Commerce with the Ingenico (Ogone) payment gateway and provides a batch process that captures all pending (authorized but uncaptured) transactions.
The module registers the batch capture page with its access callback set to always allow access, so no permission is required. Any user, including anonymous visitors, can reach the form and start the batch that captures every pending transaction against the payment gateway.
This vulnerability is mitigated by the fact that funds are only captured for transactions that are already pending, and the capture must succeed against the configured Ingenico gateway credentials.
Solution
Install the latest version.
If you use the Commerce Ingenico module for Drupal 7, upgrade to Commerce Ingenico 7.x-1.7:
Reported by
Fixed by
- Tag1 D7ES
Coordinated by
- Tag1 D7ES