Impact
An incorrect authorization flaw in Drupal Commerce PayPal permits forceful browsing, letting an attacker access pages or functions that should be restricted to legitimate users. The vulnerability is a missing or incorrect authorization check, identified as CWE-863. Successful exploitation can allow the attacker to retrieve sensitive order information, modify cart details, or perform privileged operations without proper authentication.
Affected Systems
Drupal Commerce PayPal from version 0.0.0 to 1.12.0 and from 2.0.0 to 2.1.3 are affected. Any site running these versions without applying the vendor’s recent fix is at risk.
Risk and Exploitability
The flaw allows an attacker to bypass normal authorization checks, presenting an opportunity to access sensitive commerce resources. No EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is through web requests or API calls that exploit the missing authorization guard. An attacker would need only a web browser or a script to attempt access to protected resources, making exploitation relatively straightforward where the module is deployed. The CVSS score of 9.1 indicates a critical severity.
OpenCVE Enrichment