CVE-2018-19188: XSS
Published Nov 14, 2018
·Updated
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fortid parameter.
Affected Software
1 affected component
Amazon payfort-php-SDK<=2018-04-26
Event History
Nov 14, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19188?
CVE-2018-19188 is considered a moderate severity vulnerability due to its potential for XSS attacks.
2
How do I fix CVE-2018-19188?
To fix CVE-2018-19188, validate and sanitize the input of the fort_id parameter in the success.php file.
3
Which versions of the Amazon Payfort-php-SDK are affected by CVE-2018-19188?
CVE-2018-19188 affects all versions of the Amazon Payfort-php-SDK up to and including 2018-04-26.
4
What type of vulnerability is CVE-2018-19188?
CVE-2018-19188 is classified as a Cross-Site Scripting (XSS) vulnerability.
5
Is it safe to use the affected Amazon Payfort-php-SDK version after CVE-2018-19188?
No, it is not safe to use the affected versions of the Amazon Payfort-php-SDK until the vulnerability has been patched.