GHSA-f83j-v8r3-vfhvMedium

Our payment integration with GiroCheckout did not properly validate payment status responses. An...

Published
July 28, 2026
Last Modified
July 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Our payment integration with GiroCheckout did not properly validate payment status responses. An attacker could use a successful payment status response from one payment and supply it to the system for a different payment, gaining access to multiple valid tickets with only one payment.

🔗 References (3)