composer›paypal/merchant-sdk-php›CVE-2017-60996.1 MEDIUMXSS vulnerability via tokenRemote attackers can inject arbitrary web script or HTML via the token parameter.