CVE-2012-5798 describes a vulnerability in the PayPal Pro PayFlow EC module for osCommerce, where the module fails to validate that the server hostname matches the domain name in an X.509 certificate. This flaw allows man-in-the-middle attackers to spoof SSL servers using any valid certificate, impacting osCommerce and PayPal PayFlow Pro Express Checkout integrations. With a CVSS score of 5.8 (Medium), this vulnerability requires medium attack complexity (AC:M) but can be exploited remotely (AV:N) without authentication (Au:N), potentially leading to partial confidentiality and integrity compromise (C:P/I:P). The EPSS score is very low, indicating a minimal likelihood of exploitation in the wild. There is no evidence of active exploitation, and no public exploit code is available via Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are also negligible, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:oscommerce:oscommerce:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:paypal:payflow_pro_express_checkout:-:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.