Description
When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
Published: 2026-07-09
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the description, it is inferred that the PayRange version 7.0.7 application contains a flaw that permits malicious JavaScript code to be injected into a WebView component when an SSL bypass is present. By executing crafted JavaScript function calls, an attacker can escape the WebView sandbox and gain the ability to run code that can compromise, extract sensitive data, or perform other unauthorized operations. This represents a code‑injection vulnerability with the potential for full device compromise.

Affected Systems

Only PayRange version 7.0.7 is listed are reported to be affected.

Risk and Exploitability

TheEPSS score indicates a very low current likelihood of exploitation, yet the CVSS score of 9.6 highlights the critical severity. Because the injected JavaScript can escape the WebView sandbox, successful exploitation would provide the attacker with remote code execution and control over the device. The vulnerability is not currently listed in CISA’s KEV catalog, but the combination with an SSL bypass makes it a serious risk for users of the vulnerable application.

Generated by OpenCVE AI on July 28, 2026 at 08:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the PayRange application to the latest version that contains a fix for the WebView injection flaw and monitor vendor advisories for patch releases.
  • Enforce strict SSL/TLS validation on all devices, and disable any transport‑layer interception or certificate pinning bypass that could enable the SSL bypass used by an attacker.
  • If an immediate application update is not possible, limit the use of the vulnerable app on critical devices or implement network and device policies that block or sandbox the WebView from executing arbitrary JavaScript.

Generated by OpenCVE AI on July 28, 2026 at 08:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Sun, 26 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Tue, 21 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Thu, 16 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Wed, 15 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Mon, 13 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Sun, 12 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Sat, 11 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Fri, 10 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Payrange
Payrange payrange
Vendors & Products Payrange
Payrange payrange

Thu, 09 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specific JavaScript function calls allows the attacker to escape the WebView sandbox and perform a number of dangerous actions on the user's device.
Title PayRange version 7.0.7 contains a JavaScript injection vulnerability
References

Subscriptions

Payrange Payrange
cve-icon MITRE

Status: PUBLISHED

Assigner: certcc

Published:

Updated: 2026-07-10T20:32:30.071Z

Reserved: 2026-06-26T20:08:29.251Z

Link: CVE-2026-13461

cve-icon Vulnrichment

Updated: 2026-07-10T19:09:15.829Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')