Payment method token being sent to 3rd party analytics service
Team Summary
Official summary from Upserve
A payment method token represents an individual payment card (credit or debit) and is unique to each merchant (i.e. one credit card will have a different token at Merchant A and Merchant B). These tokens may only be used with the merchant that generated them. When using Online Ordering, payment method tokens were inadvertently being sent to a 3rd party analytics service. The 3rd party service was not storing the tokens. The exposure is quite limited because to make use of the token an attacker would have had to be positioned within the 3rd party service. Our configuration has been updated to no longer send these tokens to the service.
Vulnerability Details
Technical details and impact analysis
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Business Logic Errors