What the vulnerability does
01Description
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
What the vulnerability does
Unauthenticated Broken Access Control in PayU India <= 3.8.9 versions.
Explanation of Vulnerability in Simple Terms
PayU India versions up to 3.8.9 lack proper authorization checks, allowing unauthenticated attackers to modify data through network requests. The vulnerability does not expose sensitive information or disrupt service availability, but enables unauthorized changes to system state. No user interaction is required to exploit this flaw.
What an attacker can do
Modify data or settings without authentication or permission.
Potential impact on your site
Unauthorized changes to payment processing configuration, transaction records, or account settings without detection of the attacker's identity.
Conditions required to exploit
Network access to the PayU India application; no authentication required.
Key dates
External resources
Related vulnerabilities