GHSA-78vr-q6cf-c7p6: Craft Commerce: Partial Payment Amount Without Lower Bound Validation
The Order::setPaymentAmount() method accepts any float value without enforcing a minimum positive amount. The PaymentsController casts the user-supplied ‘paymentAmount’ parameter directly to float with no lower-bound check.
References
Code Behaviors & Features
Detect and mitigate GHSA-78vr-q6cf-c7p6 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →