Remote Code Execution in osCommerce PayPal Module by PayPal
CVE-2012-2991

Currently unrated

Key Information:

Vendor

Oscommerce

Vendor
CVE Published:
19 September 2012

What is CVE-2012-2991?

The PayPal module for osCommerce Online Merchant, prior to version 2.3.4, is susceptible to a security flaw that permits remote attackers to manipulate the merchant's email address field within payment transactions. This vulnerability allows attackers to redirect funds intended for legitimate merchants to themselves, thereby compromising the integrity of the payment processing system. Proper validation of the payment recipient's email address is crucial to prevent unauthorized modifications.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.