Impact
The vulnerability is an improper verification of a cryptographic signature in the PrestaShop Virtual POS Module, allowing attackers to forge payment signatures and bypass strict validation checks. This flaw, identified as CWE-347, can enable malicious transactions to be processed without detection, compromising the integrity and authenticity of electronic payments.
Affected Systems
PrestaShop Virtual POS Module by Sipay Electronic Money and Payment Services Inc. is vulnerable in all releases from 26.8.1 up to but not including 26.9.1. Any site running these versions is at risk unless changes are applied.
Risk and Exploitability
With a CVSS score of 9.8, this issue represents high severity. The EPSS score is not available, so precise exploitation probability is unknown, but the lack of a KEV listing does not diminish the potential impact. The likely attack vector is remote, whereby an adversary sends forged signed requests to the module’s API or web interface, potentially from the public Internet. Once exploited, the attacker can submit fraudulent payment data and compromise financial integrity.
OpenCVE Enrichment