CyberRota Analysis
AI-GeneratedThe Zarinpal Gateway versions up to 5.1.0 are vulnerable to an unauthenticated Cross Site Request Forgery (CSRF) attack, which could allow an attacker to perform unauthorized actions on behalf of users without their consent. This vulnerability poses a medium risk, particularly for organizations that utilize Zarinpal for payment processing, as it could lead to unauthorized transactions or data exposure. Businesses relying on this payment gateway should prioritize patching or mitigating this vulnerability to safeguard their operations and customer data.
CVE
CVE-2026-65460
Severity
MEDIUM
CVSS
4.3
EPSS
0.11%
Original NVD Description
Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.