CVE-2012-2991: Medium severity osCommerce Online Merchant vulnerability
The PayPal (aka MODULEPAYMENTPAYPALSTANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2012-2991?
CVE-2012-2991 has been classified as a medium severity vulnerability due to its impact on payment functionality.
How do I fix CVE-2012-2991?
To fix CVE-2012-2991, upgrade the osCommerce Online Merchant to version 2.3.4 or newer.
Who is affected by CVE-2012-2991?
CVE-2012-2991 affects users of the osCommerce Online Merchant versions prior to 2.3.4 using the PayPal Standard module.
What can attackers do with CVE-2012-2991?
Attackers can manipulate the payment recipient by altering the merchant's email address during transactions.
Is there a patch available for CVE-2012-2991?
There is no specific patch; the issue is resolved through software upgrade to a non-vulnerable version.