What the vulnerability does
01Description
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
What the vulnerability does
Subscriber Sensitive Data Exposure in Payment Forms for Paystack <= 4.0.5 versions.
Explanation of Vulnerability in Simple Terms
Payment Forms for Paystack versions up to 4.0.5 expose sensitive system information to authenticated users. An attacker with low-level account access can retrieve configuration details or internal data not intended for their privilege level. The vulnerability requires valid login credentials but does not require user interaction beyond authentication.
What an attacker can do
Read sensitive system information or configuration data they should not have access to.
Potential impact on your site
Authenticated users can view internal configuration or system details, potentially exposing API keys or payment settings.
Conditions required to exploit
Attacker must have a low-privilege account on the site (e.g., subscriber or contributor role).
Key dates
External resources
Related vulnerabilities