Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown

CVE-2016-15015

Disclosure Date: January 08, 2023 (last updated February 24, 2025)
A vulnerability, which was classified as problematic, was found in viafintech Barzahlen Payment Module PHP SDK up to 2.0.0. Affected is the function verify of the file src/Webhook.php. The manipulation leads to observable timing discrepancy. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as 3e7d29dc0ca6c054a6d6e211f32dae89078594c1. It is recommended to upgrade the affected component. VDB-217650 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2021-43678

Disclosure Date: December 17, 2021 (last updated February 23, 2025)
Wechat-php-sdk v1.10.2 is affected by a Cross Site Scripting (XSS) vulnerability in Wechat.php.
Attacker Value
Unknown

CVE-2019-20455

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
Gateways/Gateway.php in Heartland & Global Payments PHP SDK before 2.0.0 does not enforce SSL certificate validations.
Attacker Value
Unknown

CVE-2017-6216

Disclosure Date: July 03, 2019 (last updated November 27, 2024)
novaksolutions/infusionsoft-php-sdk v2016-10-31 is vulnerable to a reflected XSS in the leadscoring.php resulting code execution
0
Attacker Value
Unknown

CVE-2018-19187

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in a success.php echo statement.
0
Attacker Value
Unknown

CVE-2018-19189

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via an arbitrary parameter name or value that is mishandled in an error.php echo statement.
0
Attacker Value
Unknown

CVE-2018-19190

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the error.php error_msg parameter.
0
Attacker Value
Unknown

CVE-2018-19188

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the success.php fort_id parameter.
0
Attacker Value
Unknown

CVE-2018-19186

Disclosure Date: November 14, 2018 (last updated November 27, 2024)
The Amazon PAYFORT payfort-php-SDK payment gateway SDK through 2018-04-26 has XSS via the route.php paymentMethod parameter.
0
Attacker Value
Unknown

CVE-2017-6215

Disclosure Date: August 02, 2018 (last updated November 27, 2024)
paypal/permissions-sdk-php is vulnerable to reflected XSS in the samples/GetAccessToken.php verification_code parameter, resulting in code execution.
0