CVE-2019-20455: Globalpayments PHP SDK
Medium severity, CVSS 5.9. EPSS: 1% chance of exploitation in the next 30 days.
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
Affected products
- Globalpayments PHP SDK: before 2.0.0 (fixed in 2.0.0)
Published 2020-02-14. Last modified 2026-06-17.