Логотип exploitDog
bind:CVE-2023-23941
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-23941

Количество 2

Количество 2

nvd логотип

CVE-2023-23941

около 3 лет назад

SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order. The problem has been fixed with version 5.4.4. As a workaround, disable the aforementioned payment methods or use the Security Plugin in version >= 1.0.21.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-vxpm-8hcp-qh27

около 3 лет назад

Payment information sent to PayPal not necessarily identical to created order

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-23941

SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order. The problem has been fixed with version 5.4.4. As a workaround, disable the aforementioned payment methods or use the Security Plugin in version >= 1.0.21.

CVSS3: 7.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-vxpm-8hcp-qh27

Payment information sent to PayPal not necessarily identical to created order

CVSS3: 7.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу