Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qw6-59g4-vvqw

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

EPSS

Процентиль: 17%
0.00257
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-841

Связанные уязвимости

nvd
около 2 месяцев назад

Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

EPSS

Процентиль: 17%
0.00257
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-841