Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2020-36124

Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by XML External Entity (XXE) injection. An authenticated attacker can compromise the private keys of a JWT token and reuse them to manipulate the access tokens to access the platform as any desired user (clients and administrators).
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 24.1%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2020-36124
  • Paxtechnology » Paxstore » Version: 7.0.8_20200511171508
    cpe:2.3:a:paxtechnology:paxstore:7.0.8_20200511171508


Contact Us

Shodan ® - All rights reserved