Lucene search

K

Stripe Security Vulnerabilities

cve
cve

CVE-2018-19249

The Stripe API v1 allows remote attackers to bypass intended access restrictions by replaying api.stripe.com /v1/tokens XMLHttpRequest data, parsing the response under the object card{}, and reading the cvc_check information if the creation is successful without charging the actual card used in the...

7.5CVSS

7.4AI Score

0.003EPSS

2019-01-03 10:29 PM
18
cve
cve

CVE-2021-21420

vscode-stripe is an extension for Visual Studio Code. A vulnerability in Stripe for Visual Studio Code extension exists when it loads an untrusted source-code repository containing malicious settings. An attacker who successfully exploited the vulnerability could run arbitrary code in the context o...

7.8CVSS

7.7AI Score

0.001EPSS

2021-04-01 10:15 PM
53
2
cve
cve

CVE-2022-24753

Stripe CLI is a command-line tool for the Stripe eCommerce platform. A vulnerability in Stripe CLI exists on Windows when certain commands are run in a directory where an attacker has planted files. The commands are stripe login, stripe config -e, stripe community, and stripe open. MacOS and Linux ...

7.7CVSS

7AI Score

0.0004EPSS

2022-03-09 11:15 PM
55
cve
cve

CVE-2022-24825

Smokescreen is a simple HTTP proxy that fogs over naughty URLs. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an o...

5.8CVSS

5.3AI Score

0.001EPSS

2022-04-19 08:15 PM
68
cve
cve

CVE-2022-29188

Smokescreen is an HTTP proxy. The primary use case for Smokescreen is to prevent server-side request forgery (SSRF) attacks in which external attackers leverage the behavior of applications to connect to or scan internal infrastructure. Smokescreen also offers an option to deny access to additional...

6.5CVSS

6.4AI Score

0.001EPSS

2022-05-21 12:15 AM
50
4
cve
cve

CVE-2023-23315

The PrestaShop e-commerce platform module stripejs contains a Blind SQL injection vulnerability up to version 4.5.5. The method stripejsValidationModuleFrontController::initContent() has sensitive SQL calls that can be executed with a trivial http call and exploited to forge a SQL injection.

9.8CVSS

9.8AI Score

0.001EPSS

2023-03-01 03:15 PM
17