PT-2025-30276 · Pavo Pay · Pavo Pay

Published

2025-07-21

·

Updated

2025-07-21

·

CVE-2025-4130

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PAVO Pay versions prior to 13.05.2025
Description A use of hard-coded credentials issue exists in PAVO Pay, allowing the reading of sensitive constants within an executable.
Recommendations Update PAVO Pay to version 13.05.2025 or later.

Fix

Using Hardcoded Credentials

Weakness Enumeration

Related Identifiers

CVE-2025-4130

Affected Products

Pavo Pay