Description
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
Published: 2026-07-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

When the PayRange app version 7.0.7 is run, a flaw, specifically a JavaScript injection (CWE‑94) flaw, permits malicious JavaScript code to be injected into a WebView component if an SSL bypass has been performed. The injected script can call specific functions that escape the WebView sandbox, allowing an attacker to execute arbitrary code on the device. The resulting vulnerability is a high‑severity code‑injection flaw that can compromise confidentiality, integrity, and availability of the user’s data.

Affected Systems

The only product explicitly known to be vulnerable is PayRange version 7.0.7. The vulnerability exists in the mobile application and is tied to the presence of an SSL bypass. No other vendors or product versions are listed.

Risk and Exploitability

The CVSS score of 9.6 signals a critical severity, but the EPSS score of less than 1% reflects that exploitation is currently rare or unobserved. Because the flaw requires an SSL bypass as a prerequisite, an attacker would first need to establish a man‑in‑the‑middle or certificate‑bypass attack, then deliver the malicious JavaScript. When successful, the attacker gains remote code execution privileges and can perform any action achievable from the device’s user context. While the vulnerability is not yet listed in CISA’s KEV catalog, its combination with a separate SSL bypass makes it a serious risk for users of the affected app.

Generated by OpenCVE AI on August 4, 2026 at 18:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update PayRange to the latest release that removes the WebView injection flaw and confirms the fix. This is the primary remediation path.
  • Ensure that the device enforces strict TLS validation and disables any certificate‑pinning or SSL‑interception mechanisms that could enable the bypass required for injection.
  • If the application cannot be updated immediately, restrict the use of PayRange on devices that handle sensitive information and isolate the app’s network traffic from untrusted internal or external networks.

Generated by OpenCVE AI on August 4, 2026 at 18:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Mon, 03 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Sun, 26 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Tue, 21 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Thu, 16 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Wed, 15 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Sun, 12 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Payrange
Payrange payrange
Vendors & Products Payrange
Payrange payrange

Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
Title PayRange version 7.0.7 contains a JavaScript injection vulnerability
References

Subscriptions

Payrange Payrange
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-10T20:32:30.071Z

Reserved: 2026-06-26T20:08:29.251Z

Link: CVE-2026-13461

cve-icon Vulnrichment

Updated: 2026-07-10T19:09:15.829Z

cve-icon NVD

Status : Deferred

Published: 2026-07-09T17:16:56.997

Modified: 2026-07-10T21:16:53.510

Link: CVE-2026-13461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T19:00:10Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')