CVE-2026-15502
MEDIUMAojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
Title source: cnaDescription
A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. The attack may be performed from remote. The vendor was contacted early about this disclosure but did not respond in any way.
References (4)
Core 4
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-377809 | AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
https://vuldb.com/vuln/377809
Signature, Permissions Required signature
permissions-required
VDB-377809 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/377809/cti
Third Party Advisory third-party-advisory
CVE-2026-15502 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-15502
Third Party Advisory third-party-advisory
Submit #844725 | AojiaoZero Antaris latest (2026-06, no formal release) SQL Injection
https://vuldb.com/submit/844725
Scores
CVSS v3
6.3
EPSS
0.0020
EPSS Percentile
9.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-74
CWE-89
Status
published
Products (1)
AojiaoZero/Antaris
1.0
Published
Jul 12, 2026
Tracked Since
Jul 12, 2026