رفتن به محتوای اصلی
بازگشت به هشدارها
پایین

VU#152953: PayRange Android app version 7.0.7 contains multiple vulnerabilities

۱۴۰۵/۰۵/۰۴
پایین
سطح هشدار
پایین

شرح هشدار

Overview PayRange is a mobile payment app that allows users to pay for vending machines, laundromats, and other unattended machines using a smartphone with Bluetooth. Two vulnerabilities were discovered in version 7.0.7 of the PayRange app that is available in the Google Play store. Description A vulnerability (CVE-2026-13462) exists in the PayRange Android app that causes invalid SSL certificates to be accepted in application WebViews. A second vulnerability (CVE-2026-13461) exists that allows the injection of JavaScript, which can be used to escape the WebView sandbox and perform a number of dangerous actions on the user's device. These vulnerabilities were discovered in version 7.0.7 of the PayRange app. The PayRange app bypasses Android's SSL trust chain and accepts certificates that match any of the following rules (including self-signed certificates): Common Name ends with "payrange.com" Common Name contains "stripe.com" Common Name contains "fetlifestatus.com" A