PCI v3.2-6.5.3
CAPEC-118
CWE-213
ISO27001-A.18.1.4
WASC-13
OWASP 2013-A6
OWASP 2017-A3

Credit Card Disclosure

Severity:
Information
Summary

Invicti identified a possible credit card number disclosure.

Impact

It is not mandatory for a merchant to require the security code for making a transaction, hence the card is still prone to fraud even if only its number is known to phishers.

Remediation

We strongly advise you not to expose credit card numbers on your website.

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.