PT-2026-56007 · Unknown · Fossbilling
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions 0.6.0 through 0.7.2
Description
A SQL injection issue exists in the
Massmailer module filter functionality. An authenticated administrator can provide crafted filter values during the update of a mass email message, which allows untrusted input to be interpolated directly into the SQL recipient selection query.Recommendations
Update to version 0.8.0.
Restrict administrator access to trusted users only.
Disable the
Massmailer module if it is not required.
Audit existing records in the mod massmailer table for suspicious filter values.
Review administrator activity related to Massmailer message updates.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fossbilling