CVE-2025-15618 is a critical vulnerability affecting Business::OnlinePayment::StoredTransaction versions through 0.01 for Perl, where an insecure secret key is generated using a cryptographically weak method (MD5 of a single rand() call) for encrypting credit card transaction data. Rated 9.1 CRITICAL, this vulnerability allows an unauthenticated attacker to exploit it over the network with low complexity, potentially leading to high confidentiality and integrity impacts, including the disclosure or tampering of sensitive payment information. While there is no evidence of active exploitation, no public exploit code, and a very low EPSS score, the vulnerability has garnered some community discussion across social media and mailing lists.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.01CPE matchmatch criteria | cpe:2.3:a:mock:business\:\:onlinepayment\:\:storedtransaction:0.01:*:*:*:*:perl:*:* | ||
>= 0, <= 0.01CPE match | cpe:2.3:a:mock:business\:\:onlinepayment\:\:storedtransaction:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.