The goodoneuz/pay-uz Laravel package (<= 2.2.24) contains a critical vulnerability in the /payment/api/editable/update endpoint that allows unauthenticated attackers to overwrite existing PHP payment hook files. The endpoint is exposed via Route::any without authentication middleware, enabling remote access without credentials.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-04-16 13:16
Updated : 2026-08-10 12:17
NVD link : CVE-2026-31843
Mitre link : CVE-2026-31843
CVE.ORG link : CVE-2026-31843
JSON object : View
Products Affected
No product.
CWE
CWE-284
Improper Access Control
