Unrated severityNVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
CVE-2026-15502
Description
A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
2- Range: 1.0
- Range: 1.0
Patches
Vulnerability mechanics
References
4- vuldb.com/cve/CVE-2026-15502mitrethird-party-advisory
- vuldb.com/submit/844725mitrethird-party-advisory
- vuldb.com/vuln/377809mitrevdb-entrytechnical-description
- vuldb.com/vuln/377809/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.