Kartpay Program Statistics


View program

19 total issues disclosed

$0 total paid publicly

Most disclosed (6 disclosures) — Information Disclosure



Disclosed Reports


Report Title Vulnerability Type Disclosed By Severity Disclosed on
Full Path Disclosure of Server through 500 Server Error Information Disclosure bugera Low 2021-08-16
Host Header Injection HTTP Request Smuggling streetdragon Medium 2021-05-10
Duplicate Entry of email leads to 500 Server Error which disclosing the SQL Database table information Information Disclosure basant0x01 Critical 2021-03-14
Disclosure of Merchant_id into the source code without entered OTP code leads to Victims MID takeover. Information Disclosure basant0x01 Critical 2021-03-08
Misconfiguration of Merchant id in jwt header + Weird Debug mode enabling behavior leads to exposed OTP of mobile number. Improper Authentication - Generic basant0x01 High 2021-01-20
Being able to change account contents even after password change Insufficient Session Expiration us3aft3rfr33 Medium 2021-01-06
Admin/Info lekage Information Disclosure abhhi Low 2020-10-24
bypass captcha in the form forgot password Violation of Secure Design Principles hami Low 2019-11-14
Referer issue in Kartpay.com Open Redirect aslanemre Medium 2019-10-28
Bypass _token in forms [Merchant.Kartpay.com ] None supplied zxdrrr None 2019-10-09
URl redirection Open Redirect ziel Medium 2019-08-28
Option method enabled in kartpay Webservers Information Disclosure lollol1 Low 2019-08-28
Application Error disclosure, Verification token seen error and user able to change password Improper Authentication - Generic amol01 No rating 2019-08-28
SMTP Failure Leads to Chain of Internal System Failure Information Disclosure bb00x High 2019-08-28
Reflected XSS on https://merchant.kartpay.com/payment_settings [status] Cross-site Scripting (XSS) - Reflected august1808 No rating 2019-08-28
XSS in https://merchant.kartpay.com/settlements None supplied c00lbugs No rating 2019-08-28
Application Design issue for Phone Number field in Registration. Information Exposure Through an Error Message eissen5c Low 2019-08-05
Captcha protection Bypass on Forgot password page Violation of Secure Design Principles bb00x Low 2019-08-05
Error Page Content Spoofing or Text Injection [https://vpn.kartpay.com/] Violation of Secure Design Principles c00lbugs No rating 2019-08-01