Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
The product does not validate, or incorrectly validates, a certificate.
Link | Tags |
---|---|
https://github.com/globalpayments/php-sdk/releases/tag/2.0.0 | third party advisory release notes |
https://github.com/globalpayments/php-sdk/compare/1.3.3...2.0.0 | release notes third party advisory patch |
https://winterdragon.ca/global-payments-vulnerability/ | url repurposed patch exploit third party advisory |
https://github.com/globalpayments/php-sdk/pull/8 | third party advisory exploit |