PT-2024-35164 · Envaysoft · Envaysoft Fleetcart
Skalvin
·
Published
2024-05-22
·
Updated
2024-06-04
·
CVE-2024-5230
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
EnvaySoft FleetCart versions up to 4.1.1
Description
A vulnerability has been found in EnvaySoft FleetCart, allowing for information disclosure through the manipulation of the
razorpayKeyId argument. The attack can be launched remotely, affecting an unknown functionality. It is recommended to upgrade the affected component to secure data.Recommendations
For EnvaySoft FleetCart versions up to 4.1.1, it is recommended to upgrade the affected component to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the
razorpayKeyId argument to minimize the risk of exploitation.Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Envaysoft Fleetcart