PT-2024-25592 · Unknown · Janobe Paypal/Card Payment

·

CVE-2024-33960

·

Published

2024-08-06

·

Updated

2024-08-15

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Janobe PayPal/Card Payment version 1.0
Description A SQL injection issue affects the payment system, allowing an attacker to send a specially crafted query to the server and retrieve stored information through the end parameter in the "/admin/mod reports/printreport.php" endpoint. This could potentially lead to unauthenticated remote code execution.
Recommendations For version 1.0, update the software to a patched version to fix the SQL injection vulnerability. As a temporary workaround, consider restricting access to the "/admin/mod reports/printreport.php" endpoint to minimize the risk of exploitation. Avoid using the end parameter in the affected endpoint until the issue is resolved.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-33960

Affected Products

Janobe Paypal/Card Payment