Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x2gq-qh4v-9777

Опубликовано: 25 июн. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.3

Описание

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

EPSS

Процентиль: 26%
0.00331
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-841

Связанные уязвимости

nvd
2 месяца назад

Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

EPSS

Процентиль: 26%
0.00331
Низкий

6.3 Medium

CVSS4

Дефекты

CWE-841