Impact
This vulnerability is a timing discrepancy flaw in PayTR's Virtual Pos iFrame API (v9x) WHMCS Module, identified as a CWE-208 (Timing Attack) weakness. An attacker can use observable response times to reverse engineer the authentication process, ultimately bypassing authentication and executing fraudulent financial transactions. The flaw directly compromises transaction integrity and exposes payment processing to unauthorized access.
Affected Systems
PayTR Virtual Pos iFrame API (v9x) WHMCS Module from PayTR Payment and Electronic Money Institution Inc. Versions prior to 9.0.3, starting with 9.0.0, are affected. The vulnerability exists only in the earlier builds and is fixed from 9.0.3 onward.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote, web‑based timing attack against the API endpoint; this inference comes from the use of timing differences in authentication responses. An attacker does not need prior access to the system but must be able to send repeated authentication requests and measure the response delays. Successful exploitation would allow the bypass of authentication, enabling the creation of unauthorized payment records.
OpenCVE Enrichment