Medium severity6.3NVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026
CVE-2026-15502
CVE-2026-15502
Description
A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
2- Range: =1.0
- Range: =1.0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.