{"id":"CVE-2017-7992","details":"Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter.","modified":"2026-07-08T10:54:46.073580Z","published":"2017-04-21T14:59:00.540Z","references":[{"type":"FIX","url":"https://github.com/hps/heartland-php/issues/28"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/hps/heartland-php","events":[{"introduced":"0"},{"last_affected":"a8174e48f60e2b575337cb13bde41b4c4f59895a"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"2.8.17"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:heartland_payment_systems:heartland-php:*:*:*:*:*:*:*:*"}}],"versions":["v2.8.17","v2.8.16","v2.8.15","v2.8.14","v2.8.13","v2.8.12","v2.8.11","v2.8.10","v2.8.9","v2.8.8","v2.8.7","v2.8.6","v2.8.5","v2.8.4","v2.8.3","v2.8.2","v2.8.1","v2.7.1","v2.6.1","v2.5.1","v2.4.1","v2.3.1","v2.2.1","v2.1.1","v2.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-7992.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}