Executive brief
PAVO Pay, a payment processing solution, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers in web requests, an attacker can bypass security checks to view data belonging to other users or the system. This could lead to the exposure of private financial or customer records, potentially impacting the organization's compliance and reputation.
Technical details
An Authorization Bypass Through User-Controlled Key (CWE-639) exists in PAVO Pay versions prior to 13.05.2025. The vulnerability occurs when the application uses a user-supplied input to access a record or object without sufficiently verifying that the user has the necessary permissions for that specific identifier. A remote, unauthenticated attacker can exploit this by modifying parameters (such as account IDs or transaction keys) in a network request to access sensitive data they are not authorized to view. The CVSS score of 7.5 reflects high confidentiality impact with no requirement for privileges or user interaction.
Affected products
- PAVO Inc. PAVO Pay before 13.05.2025
Timeline
- 2025-07-21: disclosed
- 2025-07-21: advisory