CVE-2020-23533
06.04.2021, 16:15
Union Pay up to 1.2.0, for web based versions contains a CWE-347: Improper Verification of Cryptographic Signature vulnerability, allows attackers to shop for free in merchants' websites and mobile apps, via a crafted authentication code (MAC) which is generated based on a secret key which is NULL.Enginsight
Vendor | Product | Version |
---|---|---|
unionpayintl | union_pay | 𝑥 ≤ 1.2.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References