Commerce PayPal
A visitor could trick the website into recording an order as paid when no money had actually been transferred. They could create false payment records in the system. They could not read any private information belonging to other customers.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youThis applies to sites using the Payflow Link payment method.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Commerce PayPal to 2.1.3 or 8.x-1.12, whichever branch you are on.
For developers: what the fix changed
The fix adds validation in the `onReturn` method of `PayflowLink.php` by verifying the `SECURETOKEN` against the order data and making a server-to-server API request to PayPal to confirm the transaction details and amount before creating the payment.
Also in this release Modernised logging to use `json_encode` instead of `print_r` and fixed PHPStan issues in `CreditMessaging.php`.
src/Plugin/Commerce/PaymentGateway/PayflowLink.php+67 −29 fixsrc/Plugin/views/area/CreditMessaging.php+8 −31