Ecommerce Systempay 1.0 Production Key Brute Force
48Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 9.3epss 0.2%
exploitation probability
0.2%top 84% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Ecommerce Systempay 1.0 contains a weak cryptographic implementation vulnerability that allows attackers to brute force the 16-character production secret key used for payment signature generation. Attackers can extract payment form data and signatures from POST requests to the payment endpoint, then use SHA1 hash comparison to iteratively test key candidates until discovering the correct production key, enabling them to forge valid payment signatures and manipulate transaction amounts.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Paiement · Ecommerce Systempaypublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/48017unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.