CVE-2018-25104: CoinGate Plugin Payment callback.php postProcess logic error
A vulnerability was found in CoinGate Plugin up to 1.2.7 on PrestaShop. It has been rated as problematic. Affected by this issue is the function postProcess of the file modules/coingate/controllers/front/callback.php of the component Payment Handler. The manipulation leads to business logic errors. The attack may be launched remotely. Upgrading to version 1.2.8 is able to address this issue. The patch is identified as 0a3097db0aec7c5d66686c142c6abaa1e126ca16. It is recommended to upgrade the affected component.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25104?
CVE-2018-25104 is rated as problematic.
Which software versions are affected by CVE-2018-25104?
CVE-2018-25104 affects CoinGate Plugin and PrestaShop Payment Handler versions up to 1.2.7.
What component is impacted by CVE-2018-25104?
CVE-2018-25104 impacts the Payment Handler component in the function postProcess of the callback.php file.
How do I fix CVE-2018-25104?
To fix CVE-2018-25104, update the CoinGate Plugin and PrestaShop Payment Handler to a version later than 1.2.7.
What type of vulnerability is CVE-2018-25104?
CVE-2018-25104 is a vulnerability that leads to potential manipulation of business logic in payment processing.