
Proof-of-concept for a reflected XSS vulnerability in TranzWare Payment Gateway 3.1.12.3.2, enabling remote unauthenticated HTML injection via crafted URLs.
TranzWare Payment Gateway 3.1.12.3.2 には、反映型クロスサイトスクリプティング(XSS)の脆弱性が存在します。リモートの未認証の攻撃者は、細工された URL を介して任意の HTML コードを実行することが可能です(CVE-2020-28414 とは異なるベクトル)。
クロスサイトスクリプティング(XSS)
TranzWare
Payment Gateway 3.1.12.3.2
リモート
true
true
https://compassplus.com/solutions/tranzware/
Vladimir Rotanov(Jet Infosystems(jet.su)、モスクワ、ロシア)