PayPal SQL Injection Vulnerability Affects Credit and Debit Card Payments
CVE-2024-33961
7.5HIGH
What is CVE-2024-33961?
A SQL injection vulnerability exists in PayPal's Credit Card and Debit Card Payment processing system, specifically in version 1.0. This flaw allows attackers to craft and send malicious SQL queries to the server via the '/admin/mod_reservation/controller.php' endpoint. By exploiting this vulnerability, an attacker could gain unauthorized access to sensitive information stored in the database, potentially compromising user data and financial transaction details.
Affected Version(s)
Janobe Credit Card 1.0
Janobe Debit Card Payment 1.0
Janobe PayPal 1.0