Impact
Based on the description, it is inferred that the PayRange version 7.0.7 application contains a flaw that permits malicious JavaScript code to be injected into a WebView component when an SSL bypass is present. By executing crafted JavaScript function calls, an attacker can escape the WebView sandbox and gain the ability to run code that can compromise, extract sensitive data, or perform other unauthorized operations. This represents a code‑injection vulnerability with the potential for full device compromise.
Affected Systems
Only PayRange version 7.0.7 is listed are reported to be affected.
Risk and Exploitability
TheEPSS score indicates a very low current likelihood of exploitation, yet the CVSS score of 9.6 highlights the critical severity. Because the injected JavaScript can escape the WebView sandbox, successful exploitation would provide the attacker with remote code execution and control over the device. The vulnerability is not currently listed in CISA’s KEV catalog, but the combination with an SSL bypass makes it a serious risk for users of the vulnerable application.
OpenCVE Enrichment