CVE-2018-19187: XSS
Published Nov 14, 2018
·Updated
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
Affected Software
1 affected component
Amazon payfort-php-SDK<=2018-04-26
Event History
Nov 14, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19187?
CVE-2018-19187 has been identified as a Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2018-19187?
To fix CVE-2018-19187, update the Amazon Payfort payfort-php-SDK to a version released after April 26, 2018.
3
What is the impact of CVE-2018-19187?
The impact of CVE-2018-19187 allows an attacker to exploit XSS vulnerabilities through manipulated parameter names or values.
4
Who is affected by CVE-2018-19187?
Users of the Amazon Payfort payfort-php-SDK version up to and including 2018-04-26 are affected by CVE-2018-19187.
5
Is CVE-2018-19187 a common vulnerability?
CVE-2018-19187 is notable among vulnerabilities due to its potential to compromise web applications using the SDK.