CVE-2025-15618
CRITICALBusiness::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key
Title source: cnaDescription
Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl uses an insecure secret key. Business::OnlinePayment::StoredTransaction generates a secret key by using a MD5 hash of a single call to the built-in rand function, which is unsuitable for cryptographic use. This key is intended for encrypting credit card transaction data.
References (3)
Scores
CVSS v3
9.1
EPSS
0.0005
EPSS Percentile
15.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-338
CWE-693
Status
published
Products (2)
MOCK/Business::OnlinePayment::StoredTransaction
< 0.01
mock/business\
\ onlinepayment\
Published
Mar 31, 2026
Tracked Since
Mar 31, 2026