PT-2021-17759 · Unknown · Tranzware E-Commerce Payment Gateway
Dmitry Tatarov
+2
·
Published
2021-03-19
·
Updated
2021-03-25
·
CVE-2021-28126
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
TranzWare e-Commerce Payment Gateway (TWEC PG) versions prior to 3.1.27.5
Description:
The issue is related to a Stored cross-site scripting (XSS) vulnerability in the index.jsp file. This vulnerability allows for the storage of malicious scripts, which can then be executed by other users, potentially leading to unauthorized actions or data theft.
Recommendations:
For versions prior to 3.1.27.5, update to version 3.1.27.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the index.jsp file until a patch is applied.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tranzware E-Commerce Payment Gateway