📦

website_payments_standard_module

Vendor: paypal

Actively Exploited 0 CISA KEV List
PoC / Exploits 0 Code Available
Total RCEs 0 Remote Access
Total CVEs 3 Total Indexed
Avg. EPSS 1.14% Exploit Prob.
Latest CVE CVE-2012-2991 Sep 19

Security Vulnerability Index

Page 1 / 1
5.0 CVSS

The PayPal (aka MODULE_PAYMENT_PAYPAL_STANDARD) module before 1.1 in osCommerce Online Merchant before 2.3.4 allows remote attackers to set the payment recipient via a modified value of the merchant's e-mail address, as demonstrated by setting the recipient to one's self.

EPSS: 1.14%