multisafepay/php-sdk is vulnerable to Timing Attacks
25
Low Risk
Affected versions of this package are vulnerable to timing attacks due to the use of non-constant-time string comparison in Notification::verifyNotification, which allows attackers to potentially infer valid values through response time measurements.
You are affected if you are using a version that falls within the vulnerable range.
multisafepay/php-sdk is vulnerable to Timing Attacks in versions 5.1.0 - 5.17.0.
Upgrade the multisafepay/php-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant