Описание
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
EPSS
Процентиль: 18%
0.00257
Низкий
Дефекты
CWE-841
Связанные уязвимости
github
2 месяца назад
Our payment integration with Computop-based payment methods did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.
EPSS
Процентиль: 18%
0.00257
Низкий
Дефекты
CWE-841