Junglewise Threat Intelligence

CVE-2025-58048: Paymenter RCE via unrestricted file upload in ticket attachments

CVE-2025-58048 · Severity: critical · CVSS 9.9 · Published 2026-06-22

Technologies: Paymenter, paymenter/paymenter (Packagist). Vendors: Paymenter, Packagist.

Executive brief

Paymenter, an open-source platform for hosting providers to manage billing and clients, contains a critical flaw in its support ticket system. An authenticated user can upload malicious files that allow them to take full control of the server. This could lead to the theft of customer data, exposure of sensitive configuration files, and complete service disruption.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in the ticket attachments functionality of Paymenter. A malicious authenticated user with low privileges can upload arbitrary files, such as PHP scripts, to the server. Because these files are stored in a web-accessible directory without sufficient execution restrictions, an attacker can execute arbitrary system commands under the context of the web server user. This allows for full application and server compromise, including database extraction and credential theft. The issue is resolved in version 1.2.11.

Affected products

  • Paymenter Paymenter < 1.2.11

Timeline

  • 2025-08-28: disclosed
  • 2025-08-28: patched: Released in v1.2.11
  • 2026-06-22: advisory

References

Related threats