Intel

AIKIDO-2024-10095

razorpay is vulnerable to Server-Side Request Forgery (SSRF)

Server-Side Request Forgery (SSRF)CVE-2023-28155 Published May 20, 2024

60

Medium Risk

This Affects:

JSrazorpay
0.0.0 - 2.9.3
Fixed in 2.9.4
Are you affected? Scan for Free

TL;DR

Due to a vulnerability in the request package (CVE-2023-28155), razorpay is vulnerable to server-side request forgery (SSRF). This vulnerability has been fixed in the patch version by replacing the request library with the axios library.

Who does this affect?

You are affected if you are using a razorpay version which is within vulnerability ranges.

Background info

razorpay is vulnerable to Server-Side Request Forgery (SSRF) in versions 0.0.0 - 2.9.3.

How to fix this

Upgrade the razorpay library to the patch version.