PT-2026-56007 · Unknown · Fossbilling

·

CVE-2026-33734

·

Published

2026-07-06

·

Updated

2026-07-07

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions 0.6.0 through 0.7.2
Description A SQL injection issue exists in the Massmailer module filter functionality. An authenticated administrator can provide crafted filter values during the update of a mass email message, which allows untrusted input to be interpolated directly into the SQL recipient selection query.
Recommendations Update to version 0.8.0. Restrict administrator access to trusted users only. Disable the Massmailer module if it is not required. Audit existing records in the mod massmailer table for suspicious filter values. Review administrator activity related to Massmailer message updates.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-33734
GHSA-JF7M-J359-2899

Affected Products

Fossbilling