CVE-2023-23941: SwagPayPal payment not sent to PayPal correctly
SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order. The problem has been fixed with version 5.4.4. As a workaround, disable the aforementioned payment methods or use the Security Plugin in version >= 1.0.21.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-23941.
What is the severity of CVE-2023-23941?
The severity of CVE-2023-23941 is high with a severity value of 7.5.
What is the affected software for CVE-2023-23941?
The affected software for CVE-2023-23941 is Shopware Swagpaypal up to version 5.4.4.
How can I fix CVE-2023-23941 vulnerability?
To fix the CVE-2023-23941 vulnerability, update your Shopware Swagpaypal installation to a version beyond 5.4.4.
Where can I find more information about CVE-2023-23941?
You can find more information about CVE-2023-23941 in the GitHub commit and security advisories provided by Shopware SwagPayPal.