OSV 1.4.0 · github-reviewed · 修改于 2021-09-24 04:58
发布时间
2020-09-01 06:54
GitHub 审查时间
2020-09-01 02:08
NVD 发布时间
—
源文件
advisories/github-reviewed/2020/08/GHSA-h698-r4hm-w94p/GHSA-h698-r4hm-w94p.json
Versions 2.x.x and earlier of paypal-ipn are affected by a validation bypass vulnerability.
paypal-ipn uses the test_ipn parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox.
A motivated attacker could craft a request string using the simulator to fool the application into entering the sandbox mode, potentially allowing purchases without valid payment.
Upgrade to version 3.0.0 or later.