在 gopay 1.5.119 之前的版本中, 文件中的 函数默认禁用了 TLS 证书验证,这使得中间人攻击者能够冒充支付提供商的 API。攻击者可以提交任意证书,以读取商户凭证、签名和交易数据,并修改支付、退款和订单查询的响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet