WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.
Published at: April 27, 2018 at 09:29PM
View on website
New vulnerability on the NVD: CVE-2013-7201
Tag: government hack NVD security
No comments: