Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Pax Technology PAXSTORE 代码问题漏洞
Vulnerability Description
PAX Technology PAXSTORE是中国百富(PAX)公司的一个应用软件。一个生态系统,可连接全球80多个国家/地区的250万个终端,数千个应用程序开发人员和180多个市场。 Pax Technology PAXSTORE v7.0.8_20200511171508版本及之前版本存在安全漏洞,经过身份验证的攻击者可利用该漏洞可以破坏JWT令牌的私钥,并重用它们来操作访问令牌,以作为任何期望的用户(客户端和管理员)访问平台。
CVSS Information
N/A
Vulnerability Type
N/A