Remote Code Execution in osCommerce PayPal Module by PayPal
CVE-2012-2991
Currently unrated
What is CVE-2012-2991?
The PayPal module for osCommerce Online Merchant, prior to version 2.3.4, is susceptible to a security flaw that permits remote attackers to manipulate the merchant's email address field within payment transactions. This vulnerability allows attackers to redirect funds intended for legitimate merchants to themselves, thereby compromising the integrity of the payment processing system. Proper validation of the payment recipient's email address is crucial to prevent unauthorized modifications.
