SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-37137

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket.

MEDIUM 5.4EPSS 0.58%

Does this matter?

Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.

Description

PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.

CVSS 3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
EPSS
0.58% probability · 46th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
techvill/paymoney
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.