This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3.
Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 08 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Paytr
Paytr paytr Virtual Pos Iframe Api (v9x) Whmcs Module |
|
| Vendors & Products |
Paytr
Paytr paytr Virtual Pos Iframe Api (v9x) Whmcs Module |
Tue, 08 Sep 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Sep 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Observable timing discrepancy vulnerability in PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module allows Black Box Reverse Engineering. This issue affects PayTR Virtual Pos iFrame API (v9x) WHMCS Module: from v9.0.0 before v9.0.3. | |
| Title | Callback Authentication Bypass via Timing Attack in PayTR's PayTR Virtual Pos iFrame API (v9x) WHMCS Module | |
| Weaknesses | CWE-208 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: TR-CERT
Published:
Updated: 2026-09-08T15:48:16.865Z
Reserved: 2026-07-17T09:10:13.007Z
Link: CVE-2026-16037
Updated: 2026-09-08T15:48:12.019Z
Status : Deferred
Published: 2026-09-08T16:18:01.997
Modified: 2026-09-08T18:34:41.780
Link: CVE-2026-16037
No data.
OpenCVE Enrichment
Updated: 2026-09-08T20:34:50Z