CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
Percentile
99.7%
This module enables you to use Ogone (Ingenico) as a payment method for Drupal Commerce.
Malicious users can trick Commerce Ogone into proceeding with the checkout process without actually going through the Ogone payment process, causing the order status to be set to checkout complete, even though no payment was processed.
The vulnerability is mitigated by the fact that the balance to be paid on affected orders remains the full amount, and no payment transaction is linked to the order.
Drupal core is not affected. If you do not use the contributed Commerce Ogone module, there is nothing you need to do.
Install the latest version:
Also see the Commerce Ogone project page.
twitter.com/drupalsecurity
www.drupal.org/contact
www.drupal.org/node/2445835
www.drupal.org/project/commerce_ogone
www.drupal.org/security-team
www.drupal.org/security-team/risk-levels
www.drupal.org/security/secure-configuration
www.drupal.org/user/262198
www.drupal.org/user/36762
www.drupal.org/user/383424
www.drupal.org/user/974302
www.drupal.org/writing-secure-code