PT-2014-5970 · Woocommerce · Woocommerce Sagepay Direct Payment Gateway

Published

2014-07-02

·

Updated

2015-08-28

·

CVE-2014-4549

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions WooCommerce SagePay Direct Payment Gateway plugin versions prior to 0.1.6.7
Description The issue concerns multiple cross-site scripting (XSS) vulnerabilities. These vulnerabilities allow remote attackers to inject arbitrary web script or HTML via the MD or PARes parameters in the pages/3DComplete.php file.
Recommendations For versions prior to 0.1.6.7, update to version 0.1.6.7 or later to resolve the issue. As a temporary workaround, consider restricting access to the pages/3DComplete.php file or avoiding the use of the MD and PARes parameters until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-4549

Affected Products

Woocommerce Sagepay Direct Payment Gateway