
Proof-of-concept for CVE-2020-28414: reflected XSS in TranzWare Payment Gateway 3.1.12.3.2. Demonstrates remote unauthenticated HTML injection via crafted URL.
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url.
Cross Site Scripting (XSS)
TranzWare
Payment Gateway 3.1.12.3.2.
Remote
true
true
Vladimir Rotanov (Jet Infosystems (jet.su), Moscow, Russia)