Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2017-02-23T21:00:00
Updated: 2024-08-05T15:18:49.780Z
Reserved: 2017-02-18T00:00:00
Link: CVE-2017-6099
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2017-02-24T02:59:01.113
Modified: 2019-03-13T17:24:52.047
Link: CVE-2017-6099
Redhat
No data.