PT-2024-20859 · Unknown · 3Dsecure 2.0

Published

2024-09-11

·

Updated

2024-10-22

·

CVE-2024-25284

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Name of the Vulnerable Software and Affected Versions 3DSecure 2.0 version 3DS Authorization Method
Description The issue concerns multiple reflected Cross-Site Scripting (XSS) vulnerabilities in the 3DS Authorization Method of 3DSecure 2.0. This vulnerability allows reflected XSS via the threeDSMethodData parameter in the threeDsMethod.jsp endpoint.
Recommendations For 3DSecure 2.0 version 3DS Authorization Method, consider restricting access to the threeDSMethodData parameter in the threeDsMethod.jsp endpoint until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Related Identifiers

CVE-2024-25284

Affected Products

3Dsecure 2.0