Intel

AIKIDO-2025-10693

globalpayments/php-sdk is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor

Exposure of Sensitive Information to an Unauthorized Actor Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

40

Medium Risk

This Affects:

PHPglobalpayments/php-sdk
1.2.2 - 13.3.6
Fixed in 13.3.7
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to the exposure of sensitive information when sending request messages to a device. Sensitive fields such as RequestId, ECRId, and other potentially sensitive data in the XML message were not properly sanitized before transmission, risking unintended disclosure. The patched version mitigates this issue by masking these fields prior to sending, ensuring better protection of user privacy and security.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

globalpayments/php-sdk is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 1.2.2 - 13.3.6.

How to fix this

Upgrade the globalpayments/php-sdk library to the patch version.