Commerce Realex / Global Payments
Anyone without logging in could fake a payment response from the payment provider. They could mark unpaid orders as paid on the website but they could not view any hidden information.
- Who could do thisAnyone visiting the site. No login needed.
- Does it apply to youA site is affected if the payment system is set up to redirect users to a full page rather than using a popup window.
- Has it been used in attacksNo sign of it.
- How urgentDrupal rates this moderately critical. Include it in your next routine update, within the month.
Tell your developerUpdate Commerce Realex / Global Payments to 3.0.2.
For developers: what the fix changed
The fix verifies the SHA hash of the payment response by calling parseResponse in RealexHppResponse.php and rejects the response if the hash check fails.
src/Controller/RealexHppResponse.php+13 −1 fix