Webshop Solution Vulnerability in Paymenter Affects PayPal Webhook Processing
CVE-2026-44583
5.3MEDIUM
What is CVE-2026-44583?
The Paymenter webshop solution allows unvalidated processing of the PAYPAL-CERT-URL HTTP header in its PayPal webhook endpoint. This flaw enables attackers to manipulate server-side HTTP requests, leading to possible coercion into sending requests to arbitrary internal or external destinations. The vulnerability can result in indirect information leakage or data exfiltration due to its blind nature, while no effective validation or allowlist checks safeguard the request handling. A patch has been implemented in version 1.5.0 to address this serious issue.
Affected Version(s)
Paymenter < 1.5.0
