vendor:
Ecommerce Systempay
by:
live3
8.8
CVSS
HIGH
Brute Force
307
CWE
Product Name: Ecommerce Systempay
Affected Version From: ALL
Affected Version To: ALL
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: MacOs
2020
Ecommerce Systempay 1.0 – Production KEY Brute Force
This exploit allows an attacker to brute force the production key of an ecommerce system using Systempay and SHA1 to crypt signature. The attacker can then modify the form data and generate a success payment return.
Mitigation:
Ensure that the production key is kept secure and is not easily guessable. Use strong authentication methods and limit the number of attempts to prevent brute force attacks.