PT-2026-56009 · Unknown · Fossbilling
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.0
Description
The Guest API 'invoice/update' endpoint lacks an authorization check. This allows an unauthenticated user who possesses an invoice hash to modify the payment gateway of an unpaid invoice by changing the
gateway id variable to any payment gateway already configured in the system. Invoice hashes may be exposed through email links, referrer headers, or shared URLs. The impact is limited by the invoice accessible from hash system setting and the requirement that the gateway must be pre-installed by an administrator.Recommendations
Update to version 0.8.0.
Exploit
Fix
Missing Authentication
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling