
🚨Critical - Paymenter Arbitrary File Upload RCE via Ticket Attachments (CVE-2025-58048) Paymenter, an open-source webshop/billing solution for hosting providers, fails to restrict file types in its ticket attachments feature. A malicious authenticated user can upload arbitrary files, including executable scripts served from the web root. This can lead to sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands running under the web server user, resulting in full remote code execution. Exploitation requires only a low-privileged authenticated account and no user interaction. 👉Upgrade to Paymenter 1.2.11.
Post summary
The post identifies a critical RCE flaw via arbitrary file upload in Paymenter, mitigated by upgrading to version 1.2.11.
