I see no validation of the amount, currency, etc. that was really transferred in the PayPal IPN handler code when the system marks a Pending order as 'Paid'. Is it really that vulnerable against an exploit when eg. the cart total price is tampered in the browser session, as it seems ? or am I missing something ? Are we supposed to check the transferred amount at PayPal manually ?
This topic was automatically closed 365 days after the last reply. New replies are no longer allowed.
Vous avez encore des questions ou avez besoin d'aide?