opencart 的安全问题是否会影响 Paypal 的安全层?
Opencart曾经存在CSRF漏洞。这显然最近已得到修复。即使如此,如果仍然存在安全问题,如果 Paypal 是唯一使用的支付网关方法,这是否重要(即 Paypal 自身的安全性是否会覆盖 opencart 或任何其他电子商务购物车的安全性?)。
Opencart used to have a CSRF vulnerability. This has lately been fixed apparently. Even so if there are still security issues does it even matter if Paypal is the only payment gateway method used (i.e does Paypal's own security override opencart's or any other e-commerce shopping cart for that matter?).
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
CSRF 已在一年多前在 OpenCart 中修复(我认为是版本 1.4.8 或 1.4.8b) - 仅在管理端完成此操作,因此它对您的支付网关等没有影响
您应该使用SSL 证书适用于您打算获取人们个人信息的任何网站,无论他们如何付款。也就是说,贝宝(标准)将使用贝宝的所有安全性,因此您无需担心这方面的问题,因为如果在此过程中任何付款详细信息丢失/被盗,他们将承担任何责任。
也就是说,我的任何网站或客户端网站都没有遇到过因贝宝安全性不佳而导致任何用户信息被盗的问题,我实际上没有听说过任何人都必须诚实,所以你处于良好状态手,如果你使用它们
CSRF was fixed over a year ago in OpenCart (version 1.4.8 or 1.4.8b I think it was) - it's only on the admin side that this was ever done, so it has no effect on your payment gateway etc
You should use an SSL certificate for any site you intend to take people's personal information, regardless of how they make payments. That said, paypal (standard) will use all of paypals security, and as such you don't need to worry about that side of things, as any liability will lay with them should any payment details be lost/stolen during that process.
That said, I've never had an issue with any of my sites or client sites where any user information has been stolen as a result of bad paypal security, not have I actually heard anyone has to be honest, so you're in good hands if you use them