What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Paytm Paytm Payment Gateway paytm-payments allows SQL Injection.This issue affects Paytm Payment Gateway: from n/a through 2.7.3.
Explanation of Vulnerability in Simple Terms
02Summary
The Paytm Payment Gateway contains a SQL injection vulnerability in versions up to 2.7.3. An authenticated administrator can inject malicious SQL commands through unfiltered input, potentially reading or modifying sensitive payment and customer data. The vulnerability requires high-level administrative access and affects the confidentiality and integrity of the payment system.
What an attacker can do
03Attacker Capabilities
Read or modify payment data and customer information via SQL injection.
Potential impact on your site
04Site Impact
Unauthorized access to payment records, customer data theft, or modification of transaction history if an admin account is compromised.
Conditions required to exploit
05Prerequisites
Attacker must have administrator-level access to the Paytm Payment Gateway.
Key dates
06Disclosure timeline
November 3, 2023
CVE published
April 28, 2026
Record updated