CVE-2018-19189: XSS
Published Nov 14, 2018
·Updated
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
Affected Software
1 affected component
Amazon payfort-php-SDK<=2018-04-26
Event History
Nov 14, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19189?
CVE-2018-19189 is considered a moderate severity vulnerability since it allows for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-19189?
To fix CVE-2018-19189, you should upgrade the Amazon Payfort-php-SDK to a version released after April 26, 2018.
3
What type of vulnerability is CVE-2018-19189?
CVE-2018-19189 is classified as a cross-site scripting (XSS) vulnerability.
4
What specific components are affected by CVE-2018-19189?
CVE-2018-19189 affects all versions of the Amazon Payfort-php-SDK up to and including 2018-04-26.
5
How can CVE-2018-19189 be exploited?
CVE-2018-19189 can be exploited by injecting arbitrary parameter names or values that are mishandled, allowing malicious scripts to be executed in the user's browser.