elegro Crypto Payment 插件(版本 1.0.1 及之前)在未配置共享密钥的情况下,仍会信任来自外部的支付通知请求,这使得未认证的攻击者可以伪造支付确认信息,并篡改任何将该共享密钥保留为默认空值的站点中的任意订单状态。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | elegro Crypto Payment | 0 ~ 1.0.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86786 | Slider Pro <= 1.0.0 - Unauthenticated Sensitive Data Disclosure via sliderpro_multiple_ima | |
| CVE-2026-94270 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Bypass and Order Manipulation via | |
| CVE-2026-94278 | File Media Renamer <= 1.3 - Author+ Arbitrary File Rename via save-attachment-compat | |
| CVE-2026-94271 | Deema Payment Gateway <= 1.1.2 - Unauthenticated Payment Confirmation Forgery via Unverifi | |
| CVE-2026-89289 | Fast Courier <= 5.2.3 - Unauthenticated Order Fulfillment Update via order-status-update R |
No comments yet