Hi, may I please reserve a CVE ID for this exploit?

JSON file is attached. Notes on the entry:

  1. I'll add the reference to our directory entry after I get the ID and we publish our writeup
  2. Thus, there will be two references (I've included Tag1's link already)
  3. The vector works out to be CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N → 8.7 (High)
  4. Attached file is actually a JSON (but I couldn't upload that)

Additional input is very welcome. As a reminder, this is not yet ready to publish (still need that ref URL) but it is ready for review.

Comments

aangel created an issue. See original summary.

greggles’s picture

Status: Active » Needs review

Thanks. Acknowledging I've seen this and adjusting status to needs review so others know its time for that.

greggles’s picture

Title: Commerce Paybox CVE Request » Commerce Paybox CVE Request - CVE-2026-0750
Status: Needs review » Needs work

OK, I reserved CVE-2026-0750 for this.

aangel’s picture

StatusFileSize
new4.31 KB

I've attached a new version with the following changes:
• set the date to the publish date from Tag1 because they got it out first (May 2025)
• changed the Package collection URL to the module URL
• added our reference URL along with Tag1's; both tagged as 3rd-party vendor advisory
• no change to the description

aangel’s picture

Bump. Ready to go?

greggles’s picture

Status: Needs work » Fixed

Thanks for the explanations in #4.

I made a few tweaks and published this.

* adjusting versions to 7.x style custom
* adding www on the package collection URL
* To be consistent with prior CVEs, the vendor should be "Drupal" not "Drupal community"
* Following previous examples - using the auto-generated description.

Those will be good things to double check for future CVEs.

Now that this issue is closed, review the contribution record.

As a contributor, attribute any organization that helped you, or if you volunteered your own time.

Maintainers, credit people who helped resolve this issue.

aangel’s picture

"Those will be good things to double check for future CVEs."

Will do.

(btw, we aligned on using the D7 version number style after this was submitted.)

greggles’s picture

> (btw, we aligned on using the D7 version number style after this was submitted.)

I wondered about that. Thanks for pointing it out.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.