CVE-2012-5801
The PayPal module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate, related to use of the PHP fsockopen function.
- Affected products
- Paypal, Prestashop
- Prestashop Ebay
- All versions
- Prestashop
- All versions
- CVSS 2.0
- 5.8 MEDIUM
- EPSS
- 0.8% (53th percentile)
- Weakness
- CWE-20
- NVD status
- Modified
- Published
- 2012-11-04
CVE-2012-5801 at NVD
No indexed exploits for CVE-2012-5801 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2012-5801 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.