DRUPAL-CONTRIB-2022-053

See a problem?
Import Source
https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce_elavon/DRUPAL-CONTRIB-2022-053.json
JSON Data
https://api.osv.dev/v1/vulns/DRUPAL-CONTRIB-2022-053
Published
2022-08-24T18:21:02Z
Modified
2026-09-10T03:45:19Z
Summary
[none]
Details

This module enables you to accept payments from the Elavon payment provider.

The module doesn't sufficiently verify that it's communicating with the correct server when using the Elavon (On-site) payment gateway, which could lead to leaking valid payment details as well as accepting invalid payment details.

This vulnerability is mitigated by the fact that an attacker must be able to spoof the Elavon DNS received by your site.

References
Credits

Affected packages

Packagist:https://packages.drupal.org/8 / drupal/commerce_elavon

Package

Name
drupal/commerce_elavon
Purl
pkg:composer/drupal/commerce_elavon?repository_url=https:%2F%2Fpackages.drupal.org%2F8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.3.0
Database specific
Show details
{
    "constraint": "<2.3.0"
}

Database specific

affected_versions
"<2.3.0"
source
"https://github.com/DrupalSecurityTeam/drupal-advisory-database/blob/main/advisories/commerce_elavon/DRUPAL-CONTRIB-2022-053.json"