The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade sylius/paypal-plugin
to version 1.3.1, 1.2.4 or higher.
sylius/paypal-plugin is a PayPal plugin for Sylius.
Affected versions of this package are vulnerable to Information Exposure. The URL to the payment page done after checkout was created with auto-incremented payment id (/pay-with-paypal/{id}
) and therefore it was easy to access for anyone, not even the order's customer. The problem is that the credit card form has a pre-filled credit card holder
field with the customer's first and last name.
Additionally, the mentioned form did not require a 3D Secure authentication.