Executive brief
A security vulnerability exists in the AojiaoZero Antaris software, specifically within its PayPal payment processing component. An attacker can exploit this flaw to interfere with the application's database, potentially leading to unauthorized access to information or disruption of payment records. This issue is particularly concerning as it affects the mechanism that handles automated payment notifications.
Technical details
A SQL injection vulnerability exists in AojiaoZero Antaris 1.0 within the PayPal IPN Payment Handler. The root cause is the improper neutralization of special elements in the 'item_number' argument passed to the _rewardPurchase function in /ipn.php. A remote attacker with low privileges can manipulate this parameter to execute arbitrary SQL commands against the backend database. This could allow for unauthorized data retrieval, modification, or deletion. As of the disclosure date, the vendor has not responded to reports, and no official patch is currently available.
Affected products
- AojiaoZero Antaris 1.0
Timeline
- 2026-07-12: advisory: NVD publication date
- 2026-07-12: disclosed: Initial disclosure via VulDB