Paypal has patched a remote code execution vulnerability, about 18 months after it was reported.
The vulnerability, rated critical by Vulnerability Lab, affected a core PayPal. “A code execution vulnerability has been discovered in the official PayPal Inc. Web Application and API,” founder and researcher Benjamin Kunz Mejr revealed.
“Successful exploitation of the vulnerability leads to unauthorized code execution , webshell injections via the POST method, unauthorized path/file value requests, targeting the application or connected module components.”
“The specific system specific arbitrary code execution vulnerability is located in the developer API portal which has a connection and access to the Paypal portal API .”
Kunz Mejr stated that the attackers had the ability to gain access to local web-server files and its settings, using a script and executing code remotely while the only thing they needed was a simple user account.
Exploiting the vulnerability required only a PayPal account with low‑level privileges and limited access, while user interaction was not necessary.
PayPal was updated in April 2013 and patched the vulnerability on October 25 of the current year.

