This repository was archived by the owner on Sep 11, 2023. It is now read-only.
No verification that the server hostname matches a domain
Package
ebay
(PrestaShop)
Affected versions
<1.3.5
Patched versions
None
The eBay module in PrestaShop does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.