First published: Thu Aug 02 2018(Updated: )
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Paypal Php Permissions Sdk | <=3.9.1 | |
composer/paypal/permissions-sdk-php | <=3.9.1 | |
<=3.9.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2017-6215.
The title of this vulnerability is 'paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.'
The severity of CVE-2017-6215 is medium (5.4).
The affected software of CVE-2017-6215 is paypal/permissions-sdk-php version 3.9.1.
To fix CVE-2017-6215, you should update paypal/permissions-sdk-php to a version that has the vulnerability patched.