Impact
The advisory describes a critical flaw in the Drupal Commerce Elavon module that affects all documented versions (*.*.). The CVE indicates an unspecified weakness that could allow manipulation of payment transaction processing. The precise technical details are not disclosed, but based on the description it is inferred that the vulnerability could enable unauthorized payment actions or expose sensitive transaction information. The weakness is categorized as CWE-20, indicating improper input validation or unchecked data handling.
Affected Systems
The affected product is Drupal Commerce Elavon. Every documented version of the module, indicated by the pattern *.*., is susceptible. Organization using Drupal Commerce Elavon should check their installed version against the vendor’s product list even though no specific version numbers are supplied.
Risk and Exploitability
CVSS score 9.8 signals critical severity. EPSS score < 1% suggests a low exploitation probability at present. The vulnerability is not listed in the CISA KEV catalog. Based on the lack of confirmed exploitation, it is inferred that the likelihood of real-world attacks remains uncertain; however, the lack of a publicly disclosed fix or patch status means the residual risk persists. The likely attack vector is over the network (web interface), but this is inferred from the context of a payment module and not explicitly stated in the advisory. Exploit potential remains high if the module is reachable over the web.
OpenCVE Enrichment