Description
The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check information if the creation is successful without charging the actual card used in the transaction.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-10957 | The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check information if the creation is successful without charging the actual card used in the transaction. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:30:04.184Z
Reserved: 2018-11-13T00:00:00.000Z
Link: CVE-2018-19249
No data.
Status : Modified
Published: 2019-01-03T22:29:00.323
Modified: 2024-11-21T03:57:38.607
Link: CVE-2018-19249
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD