globalpayments/php-sdk is vulnerable to Cross-site Scripting (XSS)
35
Low Risk
Affected versions of this package are vulnerable to cross-site scripting (XSS) in example code that renders user-supplied values into HTML output without proper escaping. The affected examples output fields derived from transaction or request data directly into the page, allowing attacker-controlled input to be interpreted as markup or script content. An attacker able to influence these values can inject arbitrary HTML or JavaScript, leading to execution in the browser when the example code is used in a web context.
You are affected if you are using the example code from a version that falls within the vulnerable range.
globalpayments/php-sdk is vulnerable to Cross-site Scripting (XSS) in versions 14.1.3 - 14.1.8.
Check if you are using the vulnerable example code and upgrade to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant