Impact
The reported issue is identified as a critical vulnerability in the Drupal Commerce Elavon module. The description states that all versions are affected, implying an unspecified flaw that could allow an attacker to manipulate the module’s behavior. Because the product is listed as unsupported, no patch is currently available, and the flaw could lead to unauthorized payment actions or data exposure. The core weakness appears to be related to improper handling of payment requests, although the precise technical details are not disclosed in the advisory.
Affected Systems
The affected product is Drupal Commerce Elavon. Every documented version of the module, indicated by the pattern *.*., is susceptible. Organization using Drupal Commerce Elavon should check their installed version against the vendor’s product list even though no specific version numbers are supplied.
Risk and Exploitability
The EPSS score is unavailable and the vulnerability is not listed in the CISA KEV catalog, but the unsupported status means that no public fix exists at present. Exploit potential remains high for a system that can be reached over the web and does not have additional controls in place. With no known confirmations of exploitation, the likelihood of attack is uncertain, but the lack of remediation creates a significant residual risk that an attacker may discover or develop a method to exploit the flaw.
OpenCVE Enrichment