Insufficient Data Verification in InstantSoft icms2 Billing Module
CVE-2026-108568
5.3MEDIUM
What is CVE-2026-108568?
A vulnerability found in InstantSoft icms2 versions up to 2.18.2 affects the validatePaypalOrder function within the Billing Module. This flaw allows attackers to manipulate the bid/sig argument, resulting in inadequate verification of data authenticity. The exploit can be executed remotely, and there has been public disclosure of the vulnerability, yet the vendor has not responded to notifications regarding the issue.
Affected Version(s)
icms2 2.18.0
icms2 2.18.1
icms2 2.18.2
