Commerce Paybox - Moderately Critical - Payment bypass vulnerability
Project
Date
Severity
Moderately Critical
Affected versions
<7.x-1.6
The Commerce Paybox module integrates with Verifone e-commerce for accepting online payments. A payment bypass vulnerability could be exploited to mark a payment as done and flag an order as completed, without the user actually entering a credit card number.