CVE-2012-4934: Tomatocart

Low severity, CVSS 3.5. EPSS: 1.3% chance of exploitation in the next 30 days.

TomatoCart 1.1.7, when the PayPal Express Checkout module is enabled in sandbox mode, allows remote authenticated users to bypass intended payment requirements by modifying a certain redirection URL.

Affected products

Published 2012-10-31. Last modified 2026-06-16.