Incorrect Authorization vulnerability in Drupal Commerce PayPal allows Forceful Browsing. This issue affects Commerce PayPal versions: from 0.0.0 to 1.12.0, from 2.0.0 to 2.1.3.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Centarro Commerce_Paypal
cpe:2.3:a:centarro:commerce_paypal:*:*:*:*:*:drupal:*:*
|
— |
1.12.0
|
|
Centarro Commerce_Paypal
cpe:2.3:a:centarro:commerce_paypal:*:*:*:*:*:drupal:*:*
|
2.0.0
|
2.1.3
|