Impact
An authenticated client of a Jexactyl instance can submit a Stripe Checkout Session that has a lower value or a mismatched currency to the /api/client/billing/stripe/process endpoint. The server accepts the session as paid without verifying that the amount_total or currency matches the referenced order or the panel’s configured billing currency. The result is that the order is processed, which can provision, renew, upgrade, or unsuspend a purchased server for less than the price that was intended to be paid. This loss of revenue and potential service abuse is a payment forgery vulnerability.
Affected Systems
The vulnerability affects all Jexactyl installations running a version prior to 4.0.5 when the billing module is enabled and a Stripe secret key is configured. Users of Jexactyl Jexactyl before the release of v4.0.5 are therefore exposed.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity risk. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, but the attack is still easily achievable by any authenticated user who can submit a payment confirmation. The attacker must have normal client authentication, which is typically granted to end users, and the system must have billing enabled with a Stripe key. The vulnerability is exploitable by simply posting a crafted request to the confirmed endpoint; no additional privileges or additional software are required.
OpenCVE Enrichment