First published: Wed Nov 14 2018(Updated: )
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Amazon Payfort PHP SDK | <=2018-04-26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19188 is considered a moderate severity vulnerability due to its potential for XSS attacks.
To fix CVE-2018-19188, validate and sanitize the input of the fort_id parameter in the success.php file.
CVE-2018-19188 affects all versions of the Amazon Payfort-php-SDK up to and including 2018-04-26.
CVE-2018-19188 is classified as a Cross-Site Scripting (XSS) vulnerability.
No, it is not safe to use the affected versions of the Amazon Payfort-php-SDK until the vulnerability has been patched.