CVE-2026-31843
The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remote access without credentials.
- Affected products
- Pay-Uz
- Fix
- Available
- CVSS 4.0
- 10.0 CRITICAL
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-284
- NVD status
- Deferred
- Published
- 2026-04-16
CVE-2026-31843 at NVD
1 known exploit for CVE-2026-31843
Proof-of-concept code and exploit modules indexed by Sploitus