PT-2026-3434 · Technical Laohu · Mpay
Baihekuz
·
Publicado
2026-01-19
·
Atualizado
2026-02-06
·
CVE-2026-1151
CVSS v3.1
5.4
Média
| Vetor | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
technical-laohu mpay versions up to 1.2.4
Description
A flaw exists in the User Center component of technical-laohu mpay. Manipulation of the
Nickname argument within an unknown function can lead to cross site scripting. The exploit is publicly available and could be used for attacks.Recommendations
Versions prior to 1.2.4 should be updated.
Exploit
Correção
XSS
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mpay