Page 1 of 1
Search found 5 matches
Re: change price before sending to Paypal
By the way, the 'fix' that Daniel Kerr posted at http://www.antropy.co.uk/blog/paypal-st ... art-1-5-x/ doesn't work. Just leaves everything in pending status. 3 years later he can't even get that right.
- Thu Nov 26, 2015 3:38 pm
- Replies 8
- Views 10123
Re: change price before sending to Paypal
This is a gaping hole in security that has never been addressed. Confirmed by Daniel Kerr himself 3 years later. And still not taken care of. What a piece of crap Opencart is.
Jump to post- Thu Nov 26, 2015 1:26 pm
- Replies 8
- Views 10123
Re: change price before sending to Paypal
The totals do get compared in opencart, please check the code of the pp standard controller and you will se the check is made. would you mind pointing out where that is? It's definitely not working if it's there. I purchased a small vqmod that runs the check but it's getting caught up in rounding e...
Jump to post- Fri Nov 20, 2015 2:10 am
- Replies 8
- Views 10123
Re: change price before sending to Paypal
Yes, that's what one would hope for but not the case. Apparently this is a very old problem - see this https://www.paypal-community.com/t5/About-Protections-Archive/Buyer-modifying-payments-made-on-OpenCart-system/td-p/473418?profile.language=en Also written about here with a link to a solution http...
Jump to post- Thu Nov 12, 2015 4:47 am
- Replies 8
- Views 10123
change price before sending to Paypal
Can't seem to find much info on what seem like a very simple exploit in v1.5.5.1 Using Paypal standard, at step 6 of checkout, a user can 'inspect elements' of the 'confirm order' button with their web browser and change the price of items before clicking 'confirm order' and sending to Paypal e.g. s...
Jump to post- Wed Nov 11, 2015 10:57 am
- Replies 8
- Views 10123
Search found 5 matches