Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Aleksey Shupletsov

Researcher fromDeiteriy Co. Ltd.
#21468of 53,632
11.4Total CVSS
Vulnerabilities · 2
Medium
2
PT-2021-20818
6.1
2021-10-11
Openway · Openway Way4 Acs · CVE-2021-35059
Name of the Vulnerable Software and Affected Versions: OpenWay WAY4 ACS versions prior to 1.2.278-2693 Description: The issue allows for XSS via the "/way4acs/enroll" action parameter. This means an attacker could potentially inject malicious scripts into the application, affecting users who interact with the vulnerable endpoint. Recommendations: For versions prior to 1.2.278-2693, update to version 1.2.278-2693 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/way4acs/enroll" endpoint until the update is applied.
PT-2021-20819
5.3
2021-10-11
Openway · Openway Way4 Acs · CVE-2021-35060
Name of the Vulnerable Software and Affected Versions: OpenWay WAY4 ACS versions prior to 1.2.278-2693 Description: The issue allows unauthenticated attackers to discover whether a specific payment card number is stored in the system by leveraging response differences. The "/way4acs/enroll" endpoint is affected. Recommendations: For versions prior to 1.2.278-2693, update to version 1.2.278-2693 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/way4acs/enroll" endpoint to minimize the risk of exploitation.