CVE Feed

    Dashboard / CVE / CVE-2026-31843

    CVE-2026-31843

    The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remote access without credentials.

    Published:Apr 16, 2026
    Last Modified:Aug 10, 2026
    EPS:Apr 16, 2026
    EPSS Score:0.02758
    CVSS Score:9.8

    Affected Products

    Vendor
    Goodoneuz
    Product
    Pay-uz

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High