Description
The Commerce PayPal module lets a Drupal Commerce store accept payments through PayPal, including the Payflow Link and PayPal Payments Advanced hosted checkout gateways.
The module trusts the values that the customer browser sends to the payment return URL when deciding whether an order was paid, so it accepts a forged result and amount and records a successful payment that never occurred. This vulnerability is mitigated by the fact that it applies only to sites using the Payflow Link or PayPal Payments Advanced gateway, that the attacker can only act on their own order, and that the return URL is protected by a redirect key that the attacker has to obtain or guess.
Solution
Install the latest version.
If you use the Commerce PayPal module for Drupal 7, upgrade to Commerce PayPal 7.x-2.8:
Reported by
Fixed by
- Tag1 D7ES
- Jonathan Sacksick (jsacksick)
- Kimberley Massey (kimberleycgm)
- Ryan Szrama (rszrama)
- Tom Ashe (tomtech)
Coordinated by
- Tag1 D7ES
- Swan Kalata (akalata) of the Drupal Security Team
- Benji Fisher (benjifisher) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team