CVE-2015-7231
17.09.2015, 16:59
The Commerce Commonwealth (CBA) module 7.x-1.x before 7.x-1.5 for Drupal does not properly validate payments, which allows remote attackers to make a failed payment appear valid via a crafted URL, related to a "response from commweb."Enginsight
Vendor | Product | Version |
---|---|---|
drupalcommerce | commerce_commonwealth | 7.x-1.0:x |
drupalcommerce | commerce_commonwealth | 7.x-1.1:x |
drupalcommerce | commerce_commonwealth | 7.x-1.2:x |
drupalcommerce | commerce_commonwealth | 7.x-1.3:x |
drupalcommerce | commerce_commonwealth | 7.x-1.4:x |
𝑥
= Vulnerable software versions
Common Weakness Enumeration