CVE-2026-108568 | InstantSoft icms2 up to 2.18.2 Billing paypal.php validatePaypalOrder bid/sig data authenticity
A vulnerability was found in InstantSoft icms2 up to 2.18.2 and classified as problematic. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component Billing Module. Executing a manipulation of the argument bid/sig can lead to insufficient verification of data authenticity.
The identification of this vulnerability is CVE-2026-108568. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.VulDB Recent EntriesRead More