PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.
History

Wed, 04 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2022-09-14T03:24:01.000Z

Updated: 2025-06-04T15:09:22.989Z

Reserved: 2022-08-01T00:00:00.000Z

Link: CVE-2022-37137

cve-icon Vulnrichment

Updated: 2024-08-03T10:21:33.167Z

cve-icon NVD

Status : Modified

Published: 2022-09-14T11:15:50.153

Modified: 2025-06-04T16:15:28.550

Link: CVE-2022-37137

cve-icon Redhat

No data.