Filtered by vendor Openwaygroup Subscriptions
Filtered by product Way4 Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-35060 1 Openwaygroup 1 Way4 2021-10-19 5.3 Medium
/way4acs/enroll in OpenWay WAY4 ACS before 1.2.278-2693 allows unauthenticated attackers to leverage response differences to discover whether a specific payment card number is stored in the system.
CVE-2021-35059 1 Openwaygroup 1 Way4 2021-10-15 6.1 Medium
OpenWay WAY4 ACS before 1.2.278-2693 allows XSS via the /way4acs/enroll action parameter.