This module enables you to pay for Commerce transactions using Paypal.
The module doesn't sufficiently validate the transaction result in certain circumstances, allowing a malicious user to mark transactions placed without payment.
This vulnerability only affects sites using the Payflow Link payment gateway.
- If you use the Commerce Paypal module for Drupal, upgrade to Commerce Paypal 2.1.3 or Commerce Paypal 8.x-1.12
- Swan Kalata (akalata) of the Drupal Security Team
- Benji Fisher (benjifisher) of the Drupal Security Team
- Neil Drumm (drumm) of the Drupal Security Team
- Greg Knaddison (greggles) of the Drupal Security Team
- Juraj Nemec (poker10) of the Drupal Security Team