PayPal SQL Injection Vulnerability Affects Credit and Debit Card Payments
CVE-2024-33964
7.5HIGH
What is CVE-2024-33964?
A SQL injection vulnerability exists in the PayPal Credit Card and Debit Card Payment Processing system, specifically in version 1.0. This weakness allows attackers to manipulate queries sent to the server through the 'id' parameter in the '/admin/mod_users/index.php' endpoint. If exploited, it can lead to unauthorized access to sensitive data stored within the application. Proper validation and sanitization of input queries are essential to mitigate this risk.
Affected Version(s)
Janobe Credit Card 1.0
Janobe Debit Card Payment 1.0
Janobe PayPal 1.0