• Advisory ID: DRUPAL-SA-CONTRIB-2010-062
  • Project: Ogone | Ubercart payment (third-party module)
  • Version: 5.x, 6.x
  • Date: 2010-June-16
  • Security risk: Critical
  • Exploitable from: Remote
  • Vulnerability: Access Bypass

Description

Ogone | Ubercart payment is a payment module for Ubercart that integrates Ogone PSP gateway as a checkout method for Ubercart.

The module does not always correctly verify the order status returned by the Ogone gateway, potentially allowing unpaid orders to be processed.

Versions affected

  • Ogone | Ubercart payment module for Drupal 5.x versions prior to 5.x-1.6
  • Ogone | Ubercart payment module for Drupal 6.x versions prior to 6.x-1.5

Drupal core is not affected. If you do not use the contributed Ogone | Ubercart payment module, there is nothing you need to do.

Solution

Install the latest version:

See also the Ogone | Ubercart payment project page.

Reported by

Fixed by

Contact

The Drupal security team can be reached at security at drupal.org or via the form at http://drupal.org/contact.