CVE-2017-6213: XSS
Published Aug 2, 2018
·Updated
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
Affected Software
2 affected components
composer/paypal/invoice-sdk-php<=3.9.0
Paypal Php Invoice Sdk<=3.9.0
Event History
Aug 2, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:58 AM
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-6213.
2
What software is affected by this vulnerability?
The paypal/invoice-sdk-php software is affected by this vulnerability.
3
What is the severity of CVE-2017-6213?
The severity of CVE-2017-6213 is medium.
4
How does the vulnerability CVE-2017-6213 work?
The vulnerability CVE-2017-6213 is a reflected cross-site scripting (XSS) vulnerability that allows for code execution by exploiting the permToken parameter in the samples/permissions.php file of paypal/invoice-sdk-php.
5
Is there a fix available for CVE-2017-6213?
Yes, there is a fix available for CVE-2017-6213. It is recommended to update to version 3.9.1 or later of paypal/invoice-sdk-php to mitigate the vulnerability.