CyberRota Analysis
AI-GeneratedThe PayPal webhook endpoint in Paymenter versions prior to 1.5.0 is vulnerable due to improper handling of the PAYPAL-CERT-URL HTTP header, allowing remote unauthenticated attackers to manipulate server-side HTTP requests to arbitrary destinations. This can lead to blind Server-Side Request Forgery (SSRF), potentially enabling attackers to probe sensitive internal services or exfiltrate data, depending on the network configuration. Organizations using affected versions should prioritize updating to version 1.5.0 to mitigate these risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /extensions/paypal/webhook processes the PAYPAL-CERT-URL HTTP header without validation, allowing attackers to control server-side HTTP request destinations. This value is passed directly into a server-side HTTP request via file_get_contents, allowing attackers to control the destination of the request. No allowlist, validation, or signature verification is applied to the header before usage. As a result, the application can be coerced into performing HTTP requests to attacker-controlled or internal network destinations. This vulnerability allows remote unauthenticated attackers to induce server-side HTTP GET requests to arbitrary external or internal endpoints. Depending on network configuration, this may lead to: blind SSRF to external attacker-controlled systems, and potential access to internal network services No direct response data is returned to the attacker (blind SSRF), but the issue may still enable sensitive network probing or data exfiltration via side channels. This issue has been fixed in version 1.5.0.