CVE-2026-31843
Critical · CVSS 9.8- CVSS
- 9.8
- nvd
- EPSS
- 2.76%
- 85th pct
- KEV
- No
- Class
- oss containerizable
- CWE-284
Description
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remote access without credentials.
Affected packages
| Packagist | goodoneuz/pay-uz | 0 → 3.0.0 |
References
Status: profiled · ingested 2026-08-10T18:00:50.000Z