Vulnerability CVE-2022-37140


Published: 2022-09-14

Description:
PayMoney 3.3 is vulnerable to Client Side Remote Code Execution (RCE). The vulnerability exists on the reply ticket function and upload the malicious file. A calculator will open when the victim who download the file open the RTF file.

 References:
https://github.com/saitamang/POC-DUMP/tree/main/PayMoney
https://paymoney.techvill.org

Copyright 2026, cxsecurity.com

 

Back to Top