CVE-2017-6215: XSS
Published Aug 2, 2018
·Updated
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verificationcode parameter, resulting in code execution.
Affected Software
2 affected components
composer/paypal/permissions-sdk-php<=3.9.1
Paypal Php Permissions Sdk<=3.9.1
Event History
Aug 2, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
May 14, 2022
Advisory Published
via GitHub·02:58 AM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2017-6215.
2
What is the title of this vulnerability?
The title of this vulnerability is 'paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.'
3
What is the severity of CVE-2017-6215?
The severity of CVE-2017-6215 is medium (5.4).
4
What is the affected software of CVE-2017-6215?
The affected software of CVE-2017-6215 is paypal/permissions-sdk-php version 3.9.1.
5
How can I fix CVE-2017-6215?
To fix CVE-2017-6215, you should update paypal/permissions-sdk-php to a version that has the vulnerability patched.