Sceawere

Vulnerability Detail

CVE-2026-108568UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

InstantSoft icms2 Authentication Bypass

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
InstantSoft
Product
icms2
Attack Type
Insufficient Verification of Data Authenticity
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was determined in InstantSoft icms2 up to 2.18.2. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component Billing Module. Executing a manipulation of the argument bid/sig can lead to insufficient verification of data authenticity. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-10-11T10:16:40.340Z",
  "pubdate": "2026-10-11T10:16:40.340Z",
  "executiveSummary": "A critical vulnerability has been identified in the Billing Module of InstantSoft icms2, affecting versions up to 2.18.2. The flaw resides in the 'validatePaypalOrder' function within 'system/controllers/billing/actions/paypal.php'.\nThe vulnerability is classified as insufficient verification of data authenticity, allowing remote attackers to manipulate transaction signals ('bid'/'sig' parameters). This bypass permits the unauthorized verification of payment status, effectively allowing users to trigger successful billing confirmations without legitimate financial transactions occurring.\nThe risk implication is significant as it facilitates financial fraud by manipulating the payment validation logic. The vulnerability is remotely exploitable, requiring no prior authentication or administrative privileges. Public disclosure of the exploit increases the likelihood of active exploitation, especially given the vendor's failure to address the vulnerability following initial disclosure. Immediate action is required to harden the billing validation process.",
  "technicalDetails": "The root cause of this vulnerability lies in the inadequate cryptographic validation or integrity verification of the callback parameters processed by the 'validatePaypalOrder' function in 'system/controllers/billing/actions/paypal.php'.\nThe component fails to properly verify the authenticity of the payload sent from the PayPal IPN (Instant Payment Notification) or similar callback mechanisms. By manipulating the 'bid' (Billing ID) and 'sig' (Signature) arguments, an attacker can supply crafted data that the system erroneously accepts as a valid, successful transaction.\nThe attack flow begins when an attacker initiates a request to the billing controller. Because the 'validatePaypalOrder' function does not enforce rigorous signature verification against a trusted source or shared secret, the application logic assumes the data integrity of the incoming parameters is intact.\nSpecifically, the application performs insufficient checking on the authenticity of the 'sig' parameter. By intercepting or forging these requests, an attacker can bypass the intended verification steps that should confirm the payment was actually processed by the PayPal gateway.\nThis allows the attacker to finalize orders, receive digital goods, or grant account credits without executing a corresponding payment in the external payment gateway. Since the logic is executed on the server-side, the manipulation occurs during the transaction processing phase, leading the system to update the internal database record for the transaction to a 'completed' state.\nThe vulnerability is exposed over the network, allowing remote, unauthenticated access to the endpoint. The lack of proper validation means there are no requirements for administrative privileges or elevated session rights to execute this attack. The exploit is currently publicly available, meaning attackers can utilize automated scripts to probe and abuse the billing system.\nPost-exploitation impact involves direct loss of revenue, unauthorized distribution of digital products, and potential corruption of financial logs within the icms2 ecosystem. The application will consistently treat manipulated requests as legitimate, providing the attacker with full control over the transaction finalization state."
}
CVE-2026-108568: InstantSoft icms2 Authentication Bypass (MEDIUM Severity, CVSS: 4.3) | Sceawere