PT-2024-20860 · Unknown · 3Dsecure 2.0

CVE-2024-25285

·

Published

2024-09-11

·

Updated

2024-10-22

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions 3DSecure 2.0 versions 3 and earlier
Description The issue allows form action hijacking via the threeDsMethod.jsp endpoint with the threeDSMethodData parameter or the threeDSMethodNotificationURL parameter. This enables modification of the destination web site for a form submission.
Recommendations For 3DSecure 2.0 versions 3 and earlier, as a temporary workaround, consider restricting access to the threeDsMethod.jsp endpoint until a patch is available. Avoid using the threeDSMethodData and threeDSMethodNotificationURL parameters in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-25285

Affected Products

3Dsecure 2.0