CVE Database
/

CVE-2014-10067

Back to search

CVE-2014-10067

Published: May 29, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

paypal-ipn before 3.0.0 uses the `test_ipn` parameter (which is set by the PayPal IPN simulator) to determine if it should use the production PayPal site or the sandbox. With a bit of time, an attacker could craft a request using the simulator that would fool any application which does not explicitly check for test_ipn in production.

VendorProductVersions

HackerOne

paypal-ipn node module

affected
<3.0.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now