SwagPayPal payment not sent to PayPal correctly
CVE-2023-23941

7.5HIGH

Key Information:

Vendor

Shopware

Vendor
CVE Published:
3 February 2023

What is CVE-2023-23941?

SwagPayPal is a PayPal integration module for Shopware platforms that enables various checkout methods including PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, and credit card transactions. A vulnerability exists where the payment amount and item list sent to PayPal may differ from the order details created within Shopware. This inconsistency can potentially lead to discrepancies in transaction processing. The issue has been addressed in version 5.4.4. Users are advised to disable the affected payment methods temporarily or utilize the Security Plugin version 1.0.21 or higher as a safeguard until the update can be applied.

Affected Version(s)

SwagPayPal < 5.4.4

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.