civo / kube100

NOTE: This repo is no longer being maintained or monitored. If you are facing any issues, you could either create an issue on the other respective repos (if any) or directly reach to us via civo.com
29 stars 2 forks source link

Fake Credit Cards Accepted in Billing #53

Closed anandrajaram21 closed 3 years ago

anandrajaram21 commented 3 years ago

When I was exploring the platform earlier today, I noticed the instances section and wanted to dig deeper into it. But it said that I needed a credit card for it. I went to the billing page to add a credit card, and tested the system with a test credit card number. And sure enough, CIVO detected that it was indeed a test credit card. But when I put in a random fake credit card number, there was no confirmation whatsoever, and the page just reloaded, and I saw a new card added to account. This is a huge vulnerability IMO, and I would like to inform you about the same. I would love it if you could implement the required measures to bring this down.