漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
PayRange version 7.0.7 contains a JavaScript injection vulnerability
Vulnerability Description
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
PayRange 代码注入漏洞
Vulnerability Description
PayRange PayRange是PayRange公司的一款为无人零售设备提供移动支付和物联网连接的端到端解决方案。 PayRange 7.0.7版本存在代码注入漏洞,该漏洞源于结合SSL绕过漏洞时,可注入JavaScript到WebView,允许攻击者逃逸WebView沙箱并在用户设备上执行危险操作。
CVSS Information
N/A
Vulnerability Type
N/A