dongyan1974 2019-04-15 08:29
浏览 87
已采纳

Prestashop 1.6退房时的金额篡改

I have a shopping cart built in Prestashop 1.6 and I have integrated HDFC Payment Gateway in it . After an security audit the bank told me "The test found one high-risk vulnerability (i.e. Amount Tampering)". Resolution- Kindly maintain the session.

I had not coded anything as Prestashop 1.6 is in built CMS and neither did i do anything with the HDFC payment gateway as they provided a pre built code from their end which is developed using Prestashop 1.6. I just installed the module from backend.

The Problem

  1. Added one item to the cart and checked out. (eg - 400 USD)
  2. On the 3rd party hdfc payment gateway page i didn't process with the payment.
  3. Opened another tab and added few more items (eg - 400 USD + 300 USD)
  4. Now back to point 2 and i processed with the amount for 400 USD and paid.
  5. In my admin panel its showing paid for 400 USD + 300 USD and two items are bought by the customer .

I have no idea how to solve this Amount related issue.

I am a newbie in Prestashop and Payment Gateway Integration.

  • 写回答

1条回答 默认 最新

  • dtx3006 2019-04-15 17:19
    关注

    The best practice with payment processing is always to double-check that the amount sent back by the bank after the payment was processed is perfectly matching with the amount of the related shopping cart in your local (PrestaShop) database.

    Here's a simplified flow chart:

    PrestaShop / HDFC flow chart

    In case you do not have programming skills, I would suggest to kindly refer to the module's developer so he/she can address that security issue.

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论

报告相同问题?

悬赏问题

  • ¥15 如何在node.js中或者java中给wav格式的音频编码成sil格式呢
  • ¥15 不小心不正规的开发公司导致不给我们y码,
  • ¥15 我的代码无法在vc++中运行呀,错误很多
  • ¥50 求一个win系统下运行的可自动抓取arm64架构deb安装包和其依赖包的软件。
  • ¥60 fail to initialize keyboard hotkeys through kernel.0000000000
  • ¥30 ppOCRLabel导出识别结果失败
  • ¥15 Centos7 / PETGEM
  • ¥15 csmar数据进行spss描述性统计分析
  • ¥15 各位请问平行检验趋势图这样要怎么调整?说标准差差异太大了
  • ¥15 delphi webbrowser组件网页下拉菜单自动选择问题