Junglewise Threat Intelligence

CVE-2014-10067: paypal-ipn validation bypass in IPN sandbox mode detection

CVE-2014-10067 · Severity: low · CVSS 3 · Published 2020-08-31

Vendors: npm.

Executive brief

paypal-ipn is a Node.js library that processes PayPal Instant Payment Notifications (IPN), which confirm online transactions. The library contains a flaw in how it determines whether to use PayPal's production or sandbox environment—an attacker can craft a malicious request using the simulator flag to bypass payment validation, potentially allowing unauthorized purchases without valid payment processing.

Technical details

The vulnerability is an authentication/validation bypass (CWE-287) in paypal-ipn versions 2.x.x and earlier. The library incorrectly trusts the test_ipn parameter (set by the PayPal IPN simulator) to determine the execution environment without proper validation. An attacker can craft a malicious request string that tricks the application into entering sandbox mode, bypassing payment verification logic. This allows purchases to complete without legitimate payment verification against PayPal's production systems. The vulnerability is exploitable remotely with no authentication or user interaction required. A fix is available in version 3.0.0 and later.

Affected products

  • andzdroid paypal-ipn 2.x.x and earlier

Timeline

  • 2020-08-31: disclosed
  • 2020-08-31: advisory: GHSA-h698-r4hm-w94p published

References