important · RCE — Hosting automation
An unauthenticated WHMCS visitor can execute code in the hosting-automation server context.
Affects
WHMCS, a self-hosted billing and web-hosting automation application commonly deployed on Internet-facing servers.
WHMCS says a forged payload can reach executable server-side processing without an account or user interaction and compromise the installation.
Detail and 2 sources
A fix has shipped, but the path has no public technical reproduction or exploit code.