VulnerabilityModified
CVE-2022-37137
PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket.
MEDIUM 5.4EPSS 0.58%
Does this matter?
Lower severity and a low EPSS score (0.58%). Track it; it rarely justifies an emergency change on its own.
Description
PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.58% probability · 46th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- techvill/paymoney
- Source
- cve@mitre.org
References
- https://github.com/saitamang/POC-DUMP/tree/main/PayMoneyExploit, Third Party Advisory
- https://paymoney.techvill.org/Vendor Advisory
- https://github.com/saitamang/POC-DUMP/tree/main/PayMoneyExploit, Third Party Advisory
- https://paymoney.techvill.org/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.