CTIWatch@ctiwatchcloudDisclosure
The post announces three high‑score CVEs, offering a link for further information but no additional technical or exploitation details.
PulsePatch.io@pulsepatchioDisclosure
The post announces CVE-2026-31843, describing how overwriting PHP payment hook files can lead to remote code execution and urges administrators to investigate and secure their installations.
Cyber Threat Observatory | Alan Turing Institute@TuringCyberObsDisclosure
Announces CVE-2026-31843 as a high‑impact flaw that allows attackers to overwrite PHP payment files in goodoneuz/pay‑uz (<=2.2.24), with a link to a detailed GitHub report.
Infoflowcloud@infoflowcloudDisclosure
The tweet discloses a critical vulnerability in the goodoneuz/pay-uz Laravel package’s payment API endpoint that permits unauthenticated attackers to intervene.
CVE@CVEnewDisclosure
A critical vulnerability (CVE-2026-31843) has been identified in the goodoneuz/pay‑uz Laravel package, affecting the /payment/api/editable/update endpoint and permitting unauthenticated attacks.
0day Signal@0dayPublishingPoC
The tweet announces CVE-2026-31843 with a CVSS score of 10.0, describes an RCE via Laravel's Route::any and file_put_contents, and provides a link to a PoC.