# CVE-2020-28414
## [Suggested description]
A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url.
## [Vulnerability Type]
Cross Site Scripting (XSS)
## [Vendor of Product]
TranzWare
## [Affected Product Code Base]
Payment Gateway 3.1.12.3.2.
## [Attack Type]
Remote
## [Impact Code execution]
true
## [Has vendor confirmed or acknowledged the vulnerability?]
true
## [Reference]
https://compassplus.com/solutions/tranzware/
## [Discoverer]
Vladimir Rotanov (Jet Infosystems (jet.su), Moscow, Russia)
[4.0K] /data/pocs/dea73042d68ea75df8b93fc8e2074336c1c6ef7a
└── [ 650] README.md
0 directories, 1 file