Intel

AIKIDO-2025-10519

globalpayments/php-sdk is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log File Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 31, 2025

20

Low Risk

This Affects:

PHPglobalpayments/php-sdk
1.0.0 - 13.3.2
Fixed in 13.3.3
Are you affected? Scan for Free

TL;DR

Affected versions may inadvertently log sensitive information when using certain terminal loggers. This can result in the exposure of confidential data such as credentials, tokens, or personally identifiable information in logs, posing a security and compliance risk, especially in shared or production environments.

Who does this affect?

You are affected if you use the globalpayments/php-sdk package.

Background info

globalpayments/php-sdk is vulnerable to Insertion of Sensitive Information into Log File in versions 1.0.0 - 13.3.2.

How to fix this

Upgrade globalpayments/php-sdk to the patch version.