Advisory Database
  • Advisories
  • Dependency Scanning
  1. composer
  2. ›
  3. swag/paypal
  4. ›
  5. CVE-2023-23941

CVE-2023-23941: Insufficient Verification of Data Authenticity

February 3, 2023 (updated February 15, 2023)

SwagPayPal is a PayPal integration for shopware/platform. If JavaScript-based PayPal checkout methods are used (PayPal Plus, Smart Payment Buttons, SEPA, Pay Later, Venmo, Credit card), the amount and item list sent to PayPal may not be identical to the one in the created order. The problem has been fixed with version 5.4.4. As a workaround, disable the aforementioned payment methods or use the Security Plugin in version >= 1.0.21.

References

  • github.com/advisories/GHSA-vxpm-8hcp-qh27
  • github.com/shopware/SwagPayPal/commit/57db5f4a57ef0a1646b509b415de9f03bf441b08
  • github.com/shopware/SwagPayPal/security/advisories/GHSA-vxpm-8hcp-qh27
  • nvd.nist.gov/vuln/detail/CVE-2023-23941

Code Behaviors & Features

Detect and mitigate CVE-2023-23941 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 5.4.4

Fixed versions

  • 5.4.4

Solution

Upgrade to version 5.4.4 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Learn more about CVSS

Source file

packagist/swag/paypal/CVE-2023-23941.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:14:39 +0000.