Security Advisory
CVE-2013-7202
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.