Impact
Improper validation of the quantity field in PayTR’s WHMCS module allows an attacker to manipulate the amount paid for a transaction. Because the module accepts the quantity value without enforcing proper constraints, a malicious user could submit a larger or smaller quantity than intended, resulting in unauthorized payment or revenue loss. The flaw falls under CWE-1284, which affects the integrity of transaction data and can lead to financial fraud.
Affected Systems
Systems that are impacted are PayTR Payment and Electronic Money Institution Inc.’s Virtual Pos iFrame API (v9x) WHMCS Module. Vulnerable versions include all releases starting with v9.0.0 up through, but not including, v9.0.3. Any WHMCS installation that uses these module versions is therefore at risk.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score is not provided, so the probability of exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector involves sending manipulated quantity values through the PayTR API. An attacker would need access to the front‑end or a valid session to perform this manipulation, which could lead to financial loss by altering transaction amounts.
OpenCVE Enrichment