What the vulnerability does
01Description
Cross-Site Request Forgery (CSRF) vulnerability in payform PayForm payform allows Stored XSS.This issue affects PayForm: from n/a through <= 2.0.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
What the vulnerability does
Cross-Site Request Forgery (CSRF) vulnerability in payform PayForm payform allows Stored XSS.This issue affects PayForm: from n/a through <= 2.0.
Explanation of Vulnerability in Simple Terms
PayForm versions 2.0 and earlier are vulnerable to cross-site request forgery (CSRF) attacks. An attacker can craft a malicious webpage that, when visited by a logged-in PayForm user, performs unwanted actions on their behalf. The attack requires the user to visit the attacker's page while authenticated. This can lead to unauthorized changes, data modification, or other actions within the PayForm application.
What an attacker can do
Perform unwanted actions on a PayForm user's account by tricking them into visiting a malicious webpage.
Potential impact on your site
Users' PayForm accounts can be compromised to perform unauthorized transactions or configuration changes without their knowledge.
Conditions required to exploit
User must be logged into PayForm and visit an attacker-controlled webpage.
Key dates
External resources
Related vulnerabilities