Описание
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.
Ссылки
- Permissions Required
- Technical Description
- Third Party Advisory
- Third Party Advisory
- Permissions Required
- Technical Description
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.2.0 (включая)
cpe:2.3:a:unionpayintl:union_pay:*:*:*:*:*:*:*:*
EPSS
Процентиль: 36%
0.00154
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-347
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.
EPSS
Процентиль: 36%
0.00154
Низкий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-347