Impact
The vulnerability arises from the PayTR Virtual Pos iFrame API (v9x) WHMCS Module accepting client IP information from untrusted HTTP headers, allowing an attacker to spoof the IP address reported to the system. This principal/identity spoofing (CWE‑348) can enable malicious actors to impersonate legitimate clients, potentially authorizing unauthorized debit operations or evading IP‑based access controls. The description notes that trusted identifiers can be exploited through such spoofing, indicating a high‑risk attack surface.
Affected Systems
Affected systems include the PayTR Payment and Electronic Money Institution Inc. PayTR Virtual Pos iFrame API (v9x) WHMCS Module. Versions from 9.0.0 up to, but not including, 9.0.3 are vulnerable. Administrators running these module versions on their WHMCS installations should be aware that the described spoofing flaw is present until a patched release is applied.
Risk and Exploitability
The CVSS score of 9.1 reflects critical severity, though the EPSS score is currently not available and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector involves sending a crafted HTTP request with manipulated IP‑related headers to the module’s API endpoint, requiring network connectivity to the host. Because the flaw relies on untrusted headers rather than authentication bypass, remote exploitation is feasible, and the attacker can achieve full control over the transaction flow and client identity checks.
OpenCVE Enrichment