Skip to content

Update-readme-to-markdown#37

Merged
ssandgren merged 1 commit intomasterfrom
Update-readme-to-markdown
Apr 7, 2025
Merged

Update-readme-to-markdown#37
ssandgren merged 1 commit intomasterfrom
Update-readme-to-markdown

Conversation

@ssandgren
Copy link
Copy Markdown
Contributor

No description provided.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 7, 2025

Logo
Checkmarx One – Scan Summary & Details362f4ed3-edc3-429a-9cbd-4f0bc76056cf

New Issues (11)

Checkmarx found the following issues in this Pull Request

Severity Issue Source File / Package Checkmarx Insight
HIGH Deserialization_of_Untrusted_Data /includes/traits/SavePaymentInstrumentTrait.php: 95
detailsThe serialized object get_results processed in deleteAllSavedPaymentInstruments in the file /includes/traits/SavePaymentInstrumentTrait.php at line...
Attack Vector
MEDIUM Broken_or_Risky_Hashing_Function /includes/controllers/WebhookController.php: 77
detailsIn receiveWebhook, the application uses a cryptographic hashing function, md5, that is considered cryptographically weak or broken, in /includes/co...
Attack Vector
MEDIUM Missing_HSTS_Header /assets/js/admin_apple_pay.js: 23
detailsThe web-application does not define an HSTS header, leaving it vulnerable to attack.
Attack Vector
MEDIUM Missing_HSTS_Header /includes/controllers/AdminController.php: 394
detailsThe web-application does not define an HSTS header, leaving it vulnerable to attack.
Attack Vector
MEDIUM Privacy_Violation /includes/gateways/Installment.php: 164
detailsMethod process_payment at line 164 of /includes/gateways/Installment.php sends user information outside the application. This may constitute a Priv...
Attack Vector
MEDIUM Privacy_Violation /includes/gateways/DirectDebitSecured.php: 125
detailsMethod process_payment at line 125 of /includes/gateways/DirectDebitSecured.php sends user information outside the application. This may constitute...
Attack Vector
MEDIUM Privacy_Violation /includes/gateways/Invoice.php: 211
detailsMethod process_payment at line 211 of /includes/gateways/Invoice.php sends user information outside the application. This may constitute a Privacy ...
Attack Vector
MEDIUM Privacy_Violation /includes/gateways/DirectDebitSecured.php: 125
detailsMethod process_payment at line 125 of /includes/gateways/DirectDebitSecured.php sends user information outside the application. This may constitute...
Attack Vector
LOW Log_Forging /includes/Util.php: 70
detailsMethod getNonceCheckedPostValue at line 70 of /includes/Util.php gets user input from element _POST. This element’s value flows through the code wi...
Attack Vector
LOW Log_Forging /includes/Util.php: 66
detailsMethod getNonceCheckedPostValue at line 66 of /includes/Util.php gets user input from element _POST. This element’s value flows through the code wi...
Attack Vector
LOW Log_Forging /includes/controllers/WebhookController.php: 39
detailsMethod receiveWebhook at line 39 of /includes/controllers/WebhookController.php gets user input from element file_get_contents. This element’s valu...
Attack Vector

@ssandgren ssandgren merged commit 363a551 into master Apr 7, 2025
2 checks passed
@ssandgren ssandgren deleted the Update-readme-to-markdown branch April 7, 2025 12:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant