osCommerce Community Support Forums: Verisign Payflow Pro module unsecure? - osCommerce Community Support Forums

Jump to content

Corporate Sponsor


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Verisign Payflow Pro module unsecure? Rate Topic: -----

#1 User is offline   rsmith Icon

  • Find Posts
  • Group: Community Member
  • Posts: 1
  • Joined: 07-October 04
  • Real Name:Ryan Smith

Posted 07 October 2004 - 08:51 PM

It seems very odd to me that the Verisign Payflow Pro module constructs hidden form fields in process_button() and then uses them in the before_process() to perform the credit card authorization. The customer could construct their own form, changing any values they want. I could create an order for $1,000.00, then build my own form and pay $0.01. The order will go thru. Why the round trip, shouldn't it just be pulling the information it needs on the before_process() from the session?

I'm guessing people double check the order with the payment or something.
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic