Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Way4
(Openwaygroup)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 2 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2021-10-11 | CVE-2021-35059 | OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter. | Way4 | 6.1 | ||
2021-10-11 | CVE-2021-35060 | /way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system. | Way4 | 5.3 |