Description
Multiple payment terminal versions contain non-persistent cross-site scripting vulnerabilities in billing and payment information input fields. Attackers can inject malicious script code through vulnerable parameters to manipulate client-side requests and potentially execute session hijacking or phishing attacks.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
3.1
Credits
Vulnerability-Lab [Research Team]
References
www.vulnerability-lab.com/get_content.php?id=2280 (Vulnerability Lab Advisory)
www.criticalgears.com/...uct/authorize-net-payment-terminal/ (Product Homepage)
www.criticalgears.com/product/paypal-pro-payment-terminal/ (Product Homepage)
www.criticalgears.com/product/stripe-payment-terminal/ (Product Homepage)
www.vulncheck.com/...ons-non-persistent-cross-site-scripting (VulnCheck Advisory: Payment Terminal Multiple Versions Non-Persistent Cross-Site Scripting)