XF 2 - Payment Gateways - suggest Security Audit re: disabling of TLS cert validation.


Active member
I note that XF 2 has a few more payment gateways available than just the traditional PayPal.

I'd like to bring attention to the following security issue; Plugins are disabling TLS certificate validation

I'm not suggesting that XF 2 has this vulnerability, but I find myself here as I did a search for the issue on my repo (1.5.22) and bdPaygateStripe addon may be susceptible (I don't have the php skills to determine this categorically).

Anyway.. more a heads-up than a suggestion.

Top Bottom