CVE-2026-108568
Received Received - Intake

Insufficient Data Authenticity Check in InstantSoft icms2 Billing Module

Vulnerability report for CVE-2026-108568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-11

Last updated on: 2026-10-11

Assigner: VulDB

Description

A vulnerability was determined in InstantSoft icms2 up to 2.18.2. The affected element is the function validatePaypalOrder of the file system/controllers/billing/actions/paypal.php of the component Billing Module. Executing a manipulation of the argument bid/sig can lead to insufficient verification of data authenticity. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-11
Last Modified
2026-10-11
Generated
2026-10-11
AI Q&A
2026-10-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
InstantSoft icms2 2.18.0
InstantSoft icms2 2.18.1
InstantSoft icms2 2.18.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability exists in InstantSoft icms2 versions up to 2.18.2, specifically in the billing module's paypal.php file. It involves insufficient verification of data authenticity due to a flaw in the validatePaypalOrder function. An attacker can manipulate the bid or sig arguments to potentially bypass authenticity checks.

Detection Guidance

This vulnerability involves insufficient verification of data authenticity in the validatePaypalOrder function of InstantSoft icms2 up to 2.18.2. To detect it, inspect the file system/controllers/billing/actions/paypal.php for improper handling of the bid/sig arguments. Check for any modifications to these parameters in HTTP requests or logs that may indicate exploitation attempts.

Impact Analysis

The vulnerability allows remote attackers to manipulate billing data authenticity checks. This could lead to unauthorized transactions or incorrect billing information being processed. The low CVSS scores suggest limited impact but potential for integrity issues in billing operations.

Compliance Impact

This vulnerability involves insufficient verification of data authenticity in the billing module of InstantSoft icms2, which could allow manipulation of transaction data. Such issues may impact compliance with regulations like GDPR (data integrity) or HIPAA (secure transactions) by potentially enabling unauthorized data alterations or fraudulent activities.

Mitigation Strategies

Immediately update InstantSoft icms2 to the latest version beyond 2.18.2. If no update is available, disable the Billing Module or restrict access to the paypal.php file. Monitor network traffic for unusual PayPal transaction requests involving bid or sig parameters.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-108568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart