Description
A vulnerability was determined in InstantSoft icms2 up to 2.18.2. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component Billing Module. Executing a manipulation of the argument bid/sig can lead to insufficient verification of data authenticity. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-10-11
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Data Integrity Compromise
Action: Apply Patch
AI Analysis

Impact

The vulnerability exists within the validatePaypalOrder function of InstantSoft icms2’s Billing Module, where manipulating the bid and sig parameters bypasses authenticity checks. This allows an attacker to forge or alter PayPal order data, potentially leading to unauthorized transactions or financial fraud. The weakness is an instance of CWE‑345, signifying insufficient verification of data authenticity. An attacker can exploit this via a remote HTTP request to the billing/paypal endpoint.

Affected Systems

Deployments running InstantSoft icms2 up to and including version 2.18.2 are affected. Installations of earlier or later releases are presumed safe if they incorporate the issue’s fix.

Risk and Exploitability

With a CVSS score of 5.3, the vulnerability falls in the medium severity range, and its EPSS score is currently unavailable. The exploitation path is simple: a remote user can craft a request to the paypal.php controller with tampered bid/sig values. The public disclosure of proof‑of‑concept code makes exploitation feasible, even though the vulnerability is not listed in CISA’s KEV catalog. Prompt mitigation is advised to prevent potential abuse.

Generated by OpenCVE AI on October 11, 2026 at 11:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Deploy the latest InstantSoft icms2 patch that corrects the validatePaypalOrder implementation; if no patch exists, upgrade to a later major release where the fix is included.
  • Restrict external access to the billing/paypal.php endpoint with web server or firewall rules, allowing only trusted internal traffic or authenticated services to reach it.
  • Implement an application‐level signature validation that recomputes the expected hash on the server side, rejects mismatched sig values, and logs all anomalies for audit purposes.

Generated by OpenCVE AI on October 11, 2026 at 11:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 11 Oct 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in InstantSoft icms2 up to 2.18.2. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component Billing Module. Executing a manipulation of the argument bid/sig can lead to insufficient verification of data authenticity. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.
Title InstantSoft icms2 Billing paypal.php validatePaypalOrder data authenticity
First Time appeared Instantsoft
Instantsoft icms2
Weaknesses CWE-345
CPEs cpe:2.3:a:instantsoft:icms2:*:*:*:*:*:*:*:*
Vendors & Products Instantsoft
Instantsoft icms2
References
Metrics cvssV2_0

{'score': 4, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:N/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Instantsoft Icms2
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-11T09:45:15.682Z

Reserved: 2026-10-10T15:04:23.213Z

Link: CVE-2026-108568

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-11T10:16:40.340

Modified: 2026-10-11T10:16:40.340

Link: CVE-2026-108568

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-11T11:30:17Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity