PT-2017-16895 · Paypal · Paypal Merchant Sdk

Jgj212

·

Published

2017-02-23

·

Updated

2022-05-14

·

CVE-2017-6099

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions PayPal PHP Merchant SDK (aka merchant-sdk-php) version 3.9.1
Description The issue concerns a cross-site scripting (XSS) vulnerability. This allows remote attackers to inject arbitrary web script or HTML via the token parameter in the GetAuthDetails.html.php file.
Recommendations For version 3.9.1, consider restricting access to the GetAuthDetails.html.php file until a patch is available, and avoid using the token parameter in this context to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-6099
GHSA-P4G7-WJHQ-9R2H

Affected Products

Paypal Merchant Sdk