PT-2024-20860 · Unknown · 3Dsecure 2.0
CVE-2024-25285
·
Published
2024-09-11
·
Updated
2024-10-22
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions
3DSecure 2.0 versions 3 and earlier
Description
The issue allows form action hijacking via the
threeDsMethod.jsp endpoint with the threeDSMethodData parameter or the threeDSMethodNotificationURL parameter. This enables modification of the destination web site for a form submission.Recommendations
For 3DSecure 2.0 versions 3 and earlier, as a temporary workaround, consider restricting access to the
threeDsMethod.jsp endpoint until a patch is available. Avoid using the threeDSMethodData and threeDSMethodNotificationURL parameters in the affected endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
3Dsecure 2.0