CVE-2017-6217: XSS
paypal/adaptivepayments-sdk-php v3.9.2 is vulnerable to a reflected XSS in the SetPaymentOptions.php resulting code execution
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6217?
The severity of CVE-2017-6217 is medium (6.1).
How does CVE-2017-6217 affect paypal/adaptivepayments-sdk-php v3.9.2?
CVE-2017-6217 affects paypal/adaptivepayments-sdk-php v3.9.2 by allowing a reflected XSS vulnerability in SetPaymentOptions.php, which may result in code execution.
How can I fix the vulnerability in paypal/adaptivepayments-sdk-php v3.9.2 (CVE-2017-6217)?
To fix the vulnerability in paypal/adaptivepayments-sdk-php v3.9.2, you should update to a version that does not contain the vulnerability or apply the necessary patches provided by the vendor.
What is the Common Weakness Enumeration (CWE) for CVE-2017-6217?
The Common Weakness Enumeration (CWE) for CVE-2017-6217 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').
Where can I find more information about CVE-2017-6217?
You can find more information about CVE-2017-6217 at the following reference: https://github.com/paypal/adaptivepayments-sdk-php/issues/87.