What the vulnerability does
01Description
Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
What the vulnerability does
Server-Side Request Forgery (SSRF) vulnerability in PhonePe PhonePe Payment Solutions.This issue affects PhonePe Payment Solutions: from n/a through 1.0.15.
Explanation of Vulnerability in Simple Terms
PhonePe Payment Solutions versions up to 1.0.15 contain a server-side request forgery vulnerability. An attacker can make the payment system send HTTP requests to internal or external systems on the attacker's behalf. No authentication is required. The vulnerability affects the confidentiality of data accessible from the server's network position.
What an attacker can do
Make the payment system send requests to internal systems or external servers to read sensitive data.
Potential impact on your site
Attackers can access internal services, read configuration data, or probe your network without direct access.
Conditions required to exploit
Network access to the vulnerable PhonePe Payment Solutions instance; no authentication required.
Key dates
External resources
Related vulnerabilities