SCA: security update for paymenter/paymenter (GHSA-5q4q-834j-g8g4)

high Tenable Self-Hosted Container Security Plugin ID 444143

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior
to 1.5.1, the checkout component improperly filters URL-writable properties, allowing authenticated users
to inject arbitrary key-value pairs into server provisioning parameters. Because bundled server extensions
prioritize these user-supplied properties over administrator-defined configurations, a regular user can
override hosting plans and resource limits at checkout without special privileges. The Checkout Livewire
component's $checkoutConfig property exposed via URL query parameters, only validating keys explicitly
defined by an extension's configuration method, allowing any undefined injected keys to bypass validation
entirely. These unsanitized keys are then stored directly in the database by the cart component and later
passed to server extensions during provisioning, enabling user-injected data to override intended
administrator settings. Depending on the active extension, this leads to unauthorized overrides of core
resource limits (such as CPU, RAM, storage, or package tiers). No administrative privileges are required
to exploit this vulnerability. This issue has been fixed in version 1.5.1. (CVE-2026-47198)

Solution

Update the paymenter/paymenter library and its related packages to version 1.5.1 or later.

See Also

https://github.com/advisories/GHSA-5q4q-834j-g8g4

Plugin Details

Severity: High

ID: 444143

Version: Revision 1.3

Type: Local

Family: SCA Checks

Published: 6/30/2026

Updated: 7/21/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.78

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:C/A:P

CVSS Score Source: CVE-2026-47198

CVSS v3

Risk Factor: High

Base Score: 8.5

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/30/2026

Vulnerability Publication Date: 6/30/2026

Reference Information

CVE: CVE-2026-47198