duncanmcclean/statamic-cargo is vulnerable to Insufficient Verification of Data Authenticity
75
High Risk
The Mollie and Stripe payment gateways in Statamic Cargo complete checkout and mark an order as paid without comparing the provider reported payment amount and currency against the order's grand total. A customer who edits their cart after starting payment can pay less than the order total or pay in a different currency, and the order is still marked as paid. The fix compares the gateway reported amount and currency against the order before finishing checkout and deletes the pending order when that comparison throws PreventCheckout.
You are affected if you are using a version that falls within the vulnerable range and you use the Mollie or Stripe payment gateways.
duncanmcclean/statamic-cargo is vulnerable to Insufficient Verification of Data Authenticity in versions 0.0.1 - 1.14.0.
Upgrade the duncanmcclean/statamic-cargo library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.