← Back
Web Application
CVE-2026-66473 high CVSS 7.5

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

Summary

Unauthenticated Broken Access Control in Xendit Payment <= 7.1.0 versions.

AI summary openai / gpt-4o

Xendit Paymentプラグインのバージョン7.1.0以下において、認証されていない状態でアクセス制御が壊れる問題が発見されました。これにより、攻撃者は特定の制限された機能にアクセスできる可能性があります。
❓ What is the problem
Xendit Paymentプラグインにおける認証されていないアクセス制御の欠如
📍 Affected scope
Xendit Paymentプラグインのバージョン7.1.0以下
🔥 Severity
この脆弱性は攻撃者に制限された機能へのアクセスを許すため高リスクです。
🔧 How to fix
7.1.1以降のバージョンにアップデートすることで修正されます。
🛡️ Workaround
プラグインの使用を一時停止するか、アクセス制御を独自に強化する。
🔍 Detection
影響を受けるバージョンを使用しているかを確認する。

References

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →