PT-2026-52633 · Unknown · Fossbilling
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions 0.5.4 through 0.7.2
Description
The
/run-patcher endpoint is accessible without authentication, allowing remote users to trigger privileged maintenance operations. These operations include configuration migrations, database schema changes (such as ALTER TABLE, DROP TABLE, and UPDATE statements), filesystem mutations (deletions and renames), and cache clearing. The endpoint lacks administrator authentication, CSRF validation, and CLI context requirements. An attacker can trigger these routines via an HTTP GET request to the /run-patcher endpoint, which may lead to denial-of-service attacks, session invalidation, or an inconsistent database state due to repeated or concurrent requests.Exploit
Fix
DoS
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fossbilling