PT-2026-56036 · Unknown · Fossbilling
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.0
Description
Low-privileged staff accounts can perform unauthorized actions through admin API endpoints. This issue stems from the
can always access module flag, which grants all staff access to specific modules, combined with unsafe parameter handling or insufficient permission checks on individual endpoints.Recommendations
Update to version 0.8.0.
Restrict staff accounts to only those who require access to sensitive settings.
Use a reverse proxy or WAF to restrict access to the affected admin API endpoints to trusted IP addresses or higher-privilege roles.
Exploit
Fix
Information Disclosure
Missing Authorization
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling