Date
Severity
Moderately Critical
Vulnerability
Payment Validation Bypass
Affected versions
<7.x-2.7

Description

The Commerce PayPal module lets a Drupal Commerce store accept payments through PayPal, including the Payflow Link and PayPal Payments Advanced hosted checkout gateways.

The module trusts the values that the customer browser sends to the payment return URL when deciding whether an order was paid, so it accepts a forged result and amount and records a successful payment that never occurred. This vulnerability is mitigated by the fact that it applies only to sites using the Payflow Link or PayPal Payments Advanced gateway, that the attacker can only act on their own order, and that the return URL is protected by a redirect key that the attacker has to obtain or guess.

Solution

Install the latest version.

If you use the Commerce PayPal module for Drupal 7, upgrade to Commerce PayPal 7.x-2.8:


Reported by

Fixed by

Coordinated by