Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rm46-7jc4-578m

Опубликовано: 29 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.

Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.

EPSS

Процентиль: 56%
0.00336
Низкий

Связанные уязвимости

nvd
больше 20 лет назад

Verisign Payflow Link, when running with empty Accepted URL fields, does not properly verify the data in the hidden AMOUNT field, which allows remote attackers to modify the price of the items that they purchase.

EPSS

Процентиль: 56%
0.00336
Низкий