Caused by two problems:
1) code does not correctly place "cvv" element in right part of XML tree.
2) payment gateway accepts "invalid" XML request due to non-strictness of schema or XML parser or both.

What happens? the transaction can succeed with invalid CVV information! (== high risk for fraud)

CommentFileSizeAuthor
#1 1542886-uc_securepayau.patch883 bytesdsobon

Comments

dsobon’s picture

StatusFileSize
new883 bytes

Patch included.

dgtlmoon’s picture

Version: 6.x-1.0 » 6.x-1.x-dev
univate’s picture

Status: Active » Reviewed & tested by the community

looks good to me

dgtlmoon’s picture

Status: Reviewed & tested by the community » Fixed

comitted

Status: Fixed » Closed (fixed)

Automatically closed -- issue fixed for 2 weeks with no activity.