CVE-2025-58048: Paymenter vulnerable to Remote Code Execution via public file uploads
The ticket attachments functionality in Paymenter allows a malicious authenticated user to upload arbitrary files.
With the ability to execute arbitrary code, this vulnerability can be exploited in numerous ways, including but not limited to:
- Extracting sensitive data from the database (e.g. customer information).
- Reading credentials from .env or other configuration files.
- Running arbitrary system commands under the web server user context.
This issue is Critical as it allows a low-privilege authenticated user to fully compromise the application and underlying server.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-58048 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →