First published: Wed Jul 10 2019(Updated: )
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
=3.9.2 | ||
composer/paypal/adaptivepayments-sdk-php | <=3.9.2 | |
Paypal Adaptive Payments Sdk | =3.9.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-6217 is medium (6.1).
CVE-2017-6217 affects paypal/adaptivepayments-sdk-php v3.9.2 by allowing a reflected XSS vulnerability in SetPaymentOptions.php, which may result in code execution.
To fix the vulnerability in paypal/adaptivepayments-sdk-php v3.9.2, you should update to a version that does not contain the vulnerability or apply the necessary patches provided by the vendor.
The Common Weakness Enumeration (CWE) for CVE-2017-6217 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
You can find more information about CVE-2017-6217 at the following reference: https://github.com/paypal/adaptivepayments-sdk-php/issues/87.