PT-2022-23831 · Paymoney · Paymoney
Saitamang
·
Published
2022-09-14
·
Updated
2022-09-16
·
CVE-2022-37137
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
PayMoney version 3.3
Description
The issue is related to Stored Cross-Site Scripting (XSS) that occurs during the process of replying to a ticket. This can be achieved by injecting a specially crafted payload into the "Message" field using the
description parameter, resulting in Stored XSS. The XSS payload can be triggered after the injection or accessed through the view ticket function.Recommendations
For PayMoney version 3.3, consider disabling the reply ticket function temporarily to prevent exploitation until a patch is available. Restrict access to the "Message" field and the
description parameter in the reply ticket function to minimize the risk of Stored XSS injection. Avoid using the description parameter in the affected function until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Paymoney