Webshop Solution Vulnerability in Paymenter Affects PayPal Webhook Processing
CVE-2026-44583

5.3MEDIUM

Key Information:

Vendor

Paymenter

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-44583?

The Paymenter webshop solution allows unvalidated processing of the PAYPAL-CERT-URL HTTP header in its PayPal webhook endpoint. This flaw enables attackers to manipulate server-side HTTP requests, leading to possible coercion into sending requests to arbitrary internal or external destinations. The vulnerability can result in indirect information leakage or data exfiltration due to its blind nature, while no effective validation or allowlist checks safeguard the request handling. A patch has been implemented in version 1.5.0 to address this serious issue.

Affected Version(s)

Paymenter < 1.5.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.