5
CVE-2012-2991
- EPSS 0.6%
- Published 19.09.2012 19:55:05
- Last modified 11.04.2025 00:51:21
- Source cret@cert.org
- Teams watchlist Login
- Open Login
The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.
Data is provided by the National Vulnerability Database (NVD)
Oscommerce ≫ Online Merchant Version <= 2.3.3
Oscommerce ≫ Online Merchant Version2.3.0
Oscommerce ≫ Online Merchant Version2.3.1
Oscommerce ≫ Online Merchant Version2.3.2
Paypal ≫ Website Payments Standard Module Version <= 1.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.6% | 0.686 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|