CVE-2020-28414: Tranzware Payment Gateway Project Tranzware Payment Gateway

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

A reflected cross-site scripting (XSS) vulnerability exists in the TranzWare Payment Gateway 3.1.12.3.2. A remote unauthenticated attacker is able to execute arbitrary HTML code via crafted url (different vector than CVE-2020-28415).

Affected products

Published 2020-11-12. Last modified 2026-06-17.