Impact
The vulnerability exists within the validatePaypalOrder function of InstantSoft icms2’s Billing Module, where manipulating the bid and sig parameters bypasses authenticity checks. This allows an attacker to forge or alter PayPal order data, potentially leading to unauthorized transactions or financial fraud. The weakness is an instance of CWE‑345, signifying insufficient verification of data authenticity. An attacker can exploit this via a remote HTTP request to the billing/paypal endpoint.
Affected Systems
Deployments running InstantSoft icms2 up to and including version 2.18.2 are affected. Installations of earlier or later releases are presumed safe if they incorporate the issue’s fix.
Risk and Exploitability
With a CVSS score of 5.3, the vulnerability falls in the medium severity range, and its EPSS score is currently unavailable. The exploitation path is simple: a remote user can craft a request to the paypal.php controller with tampered bid/sig values. The public disclosure of proof‑of‑concept code makes exploitation feasible, even though the vulnerability is not listed in CISA’s KEV catalog. Prompt mitigation is advised to prevent potential abuse.
OpenCVE Enrichment