Vulnerabilities > CVE-2021-28110 - XXE vulnerability in Compassplus Tranzware E-Commerce Payment Gateway

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
compassplus
CWE-611

Summary

/exec in TranzWare e-Commerce Payment Gateway (TWEC PG) before 3.1.27.5 had a vulnerability in its XML parser.

Vulnerable Configurations

Part Description Count
Application
Compassplus
1