PT-2026-95143 · Unknown · Mythicaldash
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MythicalDash versions prior to 3.5.4-aurora
Description
An unauthenticated payment bypass exists in the Stripe success-redirect mechanism. The endpoint '/api/stripe/process' creates a pending payment record before checkout is completed and includes a payment code in the success redirect. Subsequently, the endpoint '/api/stripe/processed' accepts this code without verifying the session, checking ownership, or confirming that the payment status is paid and the total amount matches the expected charge. An authenticated user can request a specific amount of coins, fail or abandon the payment, and then submit the pending code to the '/api/stripe/processed' endpoint. This allows the
StripeDB::isPending() function to trigger User::addCreditsAtomic(), granting unpaid credits and marking the transaction as processed. This flaw enables arbitrary free virtual-currency top-ups, leading to financial loss through the unauthorized consumption of hosting resources.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Insufficient Verification of Data Authenticity
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mythicaldash