First published: Thu Aug 02 2018(Updated: )
paypal/invoice-sdk-php is vulnerable to reflected XSS in samples/permissions.php via the permToken parameter, resulting in code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paypal Php Invoice Sdk | <=3.9.0 | |
composer/paypal/invoice-sdk-php | <=3.9.0 | |
<=3.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-6213.
The paypal/invoice-sdk-php software is affected by this vulnerability.
The severity of CVE-2017-6213 is medium.
The vulnerability CVE-2017-6213 is a reflected cross-site scripting (XSS) vulnerability that allows for code execution by exploiting the permToken parameter in the samples/permissions.php file of paypal/invoice-sdk-php.
Yes, there is a fix available for CVE-2017-6213. It is recommended to update to version 3.9.1 or later of paypal/invoice-sdk-php to mitigate the vulnerability.