Impact
This vulnerability is an incorrect authorization flaw that allows forceful browsing of protected resources in the Drupal Commerce Realex / Global Payments module. Attackers can access payment processing pages or transaction data that should be restricted, enabling unauthorized viewing weakness is a classic access control failure classified as CWE‑863.
Affected Systems
Drupal sites using the Commerce Realex / Global Payments module, all released versions from 0.0.0 up to and including 3.0.2, are affected.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, but the EPSS of <1% suggests the likelihood of exploitation is very low. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers could potentially target the web interface by crafting URLs to bypass authorization checks. While no active exploitation reports are known, sites that expose payment processing pages without proper role restrictions face significant risk.
OpenCVE Enrichment