CVE-2018-19190: XSS
Published Nov 14, 2018
·Updated
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php errormsg parameter.
Affected Software
1 affected component
Amazon payfort-php-SDK<=2018-04-26
Event History
Nov 14, 2018
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-19190?
CVE-2018-19190 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) exploitation.
2
How do I fix CVE-2018-19190?
To fix CVE-2018-19190, upgrade to a version of the Amazon Payfort-php-SDK released after April 26, 2018.
3
What type of vulnerability is CVE-2018-19190?
CVE-2018-19190 is a cross-site scripting (XSS) vulnerability.
4
Where is CVE-2018-19190 located in the software?
CVE-2018-19190 is located in the error.php file where the error_msg parameter is processed.
5
Who is affected by CVE-2018-19190?
Developers using the Amazon Payfort-php-SDK version up to and including April 26, 2018, are affected by CVE-2018-19190.