PT-2025-35120 · Unknown+2 · Cloudflared+2
Blackholered
·
Published
2025-08-28
·
Updated
2025-08-29
·
CVE-2025-58048
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Paymenter versions prior to 1.2.11
Description
Paymenter is a free and open-source webshop solution for hostings. The ticket attachments functionality allows a malicious authenticated user to upload arbitrary files. This could result in sensitive data extraction from the database, credentials being read from configuration files, and arbitrary system commands being run under the web server user context.
Recommendations
Upgrade to version 1.2.11 or later.
Update nginx configuration to download attachments instead of executing them.
Disallow access to
/storage/ using a WAF such as Cloudflare.Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudflared
Paymenter
Nginx