📦 Credit Card

by Janobe

🔍 What is Credit Card?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-33970

CRITICAL CVSS 9.8 Aug 6, 2024

A critical SQL injection vulnerability in the PayPal, Credit Card and Debit Card Payment module allows attackers to execute arbitrary SQL queries through the 'studid' parameter in '/candidate/controll...

CVE-2024-33972

CRITICAL CVSS 9.8 Aug 6, 2024

A critical SQL injection vulnerability in Janobe products' payment module allows attackers to execute arbitrary SQL queries through the '/report/event_print.php' endpoint. This affects systems running...

CVE-2024-33964

CRITICAL CVSS 9.8 Aug 6, 2024

A critical SQL injection vulnerability exists in the PayPal, Credit Card and Debit Card Payment module version 1.0, allowing attackers to execute arbitrary SQL queries through the 'id' parameter in '/...

CVE-2024-33966

CRITICAL CVSS 9.8 Aug 6, 2024

This is a critical SQL injection vulnerability in the payment module affecting version 1.0 of unspecified Janobe products. Attackers can exploit it to extract all database information through the 'xts...

CVE-2024-33968

CRITICAL CVSS 9.8 Aug 6, 2024

This SQL injection vulnerability in a payment module allows attackers to execute arbitrary SQL queries through the 'Attendance' and 'YearLevel' parameters. Attackers can potentially extract all databa...

CVE-2024-33960

CRITICAL CVSS 9.8 Aug 6, 2024

This is a critical SQL injection vulnerability in a payment processing component that allows attackers to execute arbitrary SQL queries. Attackers can retrieve all data from the database by exploiting...

CVE-2024-33962

CRITICAL CVSS 9.8 Aug 6, 2024

This CVE describes a critical SQL injection vulnerability in a payment module, allowing attackers to execute arbitrary SQL queries via a crafted 'code' parameter in an admin script. It affects version...

CVE-2024-33959

CRITICAL CVSS 9.8 Aug 6, 2024

This SQL injection vulnerability in PayPal, Credit Card and Debit Card Payment version 1.0 allows attackers to execute arbitrary SQL queries through the 'categ' parameter in '/admin/mod_reports/printr...

CVE-2024-33980

HIGH CVSS 7.1 Aug 6, 2024

This is a Cross-Site Scripting (XSS) vulnerability in a payment module that allows attackers to steal session cookies via a malicious URL. It affects users of the vulnerable payment module version 1.0...