Intel

AIKIDO-2024-10547

horstoeko/zugferd is vulnerable to Information Disclosure

Information Disclosure Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

PHPhorstoeko/zugferd
0.1.11 - 1.0.98
Fixed in 1.0.99

TL;DR

Affected versions of this package improperly expose payment card numbers to users, violating compliance standards and potentially leading to sensitive data breaches.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

horstoeko/zugferd is vulnerable to Information Disclosure in versions 0.1.11 - 1.0.98.

How to fix this

Upgrade the horstoeko/zugferd library to the patch version.