CVE-2025-58048Patch

LOWCVSS 9.9 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Paymenter is a free and open-source webshop solution for hostings. Prior to version 1.2.11, the ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files. This could result in sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands being run under the web server user context. This vulnerability was patched by commit 87c3db4 and was released under the version 1.2.11 tag without any other code modifications compared to version 1.2.10. If upgrading is not immediately possible, administrators can mitigate this vulnerability with one or more of the following measures: updating nginx config to download attachments instead of executing them or disallowing access to /storage/ fully using a WAF such as Cloudflare.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-06-22: 1Patch / Workaround · 2026-06-22: 1Technical Details · 2026-06-22: 106-22
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Paymenter Arbitrary File Upload RCE via Ticket Attachments (CVE-2025-58048) Paymenter, an open-source webshop/billing solution for hosting providers, fails to restrict file types in its ticket attachments feature. A malicious authenticated user can upload arbitrary files, including executable scripts served from the web root. This can lead to sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands running under the web server user, resulting in full remote code execution. Exploitation requires only a low-privileged authenticated account and no user interaction. 👉Upgrade to Paymenter 1.2.11.

    Post summary

    The post identifies a critical RCE flaw via arbitrary file upload in Paymenter, mitigated by upgrading to version 1.2.11.

    0000084
    226 followersView on X

Explore more