VYPR
Unrated severityNVD Advisory· Published Jul 12, 2026· Updated Jul 13, 2026

AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection

CVE-2026-15502

Description

A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

2

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.