PT-2026-56010 · Unknown · Fossbilling
CVSS v4.0
9.2
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions 0.6.0 through 0.7.2
Description
An unauthenticated payment bypass exists in the IPN callback endpoint
/ipn.php. When the Custom payment adapter is enabled, an attacker can mark any unpaid invoice as paid and credit the associated client account without making an actual payment by sending a single crafted HTTP request.Recommendations
Update to version 0.8.0.
Disable the Custom payment gateway if not actively needed.
Restrict access to the
/ipn.php endpoint at the web server level using IP allowlisting.Exploit
Fix
Origin Validation Error
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling