CVE-2014-10067 describes a vulnerability in paypal-ipn before version 3.0.0, where the application improperly uses the test_ipn parameter to distinguish between production and sandbox environments. An attacker could exploit this by crafting a request from the PayPal IPN simulator, potentially tricking applications that don't explicitly validate this parameter. This medium-severity vulnerability (CVSS 5.9) has a network attack vector and high confidentiality impact, but requires high attack complexity. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.0.0CPE matchmatch criteria | cpe:2.3:a:paypal-ipn_project:paypal-ipn:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.