What the vulnerability does
01Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
What the vulnerability does
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PayPlus LTD PayPlus Payment Gateway.This issue affects PayPlus Payment Gateway: from n/a through 7.0.7.
Explanation of Vulnerability in Simple Terms
PayPlus Payment Gateway versions up to 7.0.7 contain a SQL injection vulnerability in a component requiring low-level authentication. An attacker with a valid user account can craft malicious input to extract sensitive data from the database, including customer payment information and site credentials. The vulnerability also allows limited disruption of service availability.
What an attacker can do
Extract sensitive data from the site database, including customer records and credentials.
Potential impact on your site
Customer payment data and site credentials may be exposed; service availability may be degraded.
Conditions required to exploit
Attacker must have a valid user account with low-level privileges on the site.
Key dates
External resources
Related vulnerabilities