Description
Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-16962 | Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter. |
References
| Link | Providers |
|---|---|
| https://github.com/hps/heartland-php/issues/28 |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T23:30:58.565Z
Reserved: 2017-04-21T00:00:00.000Z
Link: CVE-2017-7992
No data.
Status : Modified
Published: 2017-04-21T14:59:00.540
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-7992
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD