PT-2026-56038 · Unknown · Fossbilling
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.0
Description
A low-privileged staff account can grant arbitrary module permissions to itself, leading to persistent privilege escalation. A user possessing the
staff.create and edit staff permission can call the /api/admin/staff/permissions update endpoint targeting their own account to write any permission structure, which bypasses the role-based access control boundary.Recommendations
Update to version 0.8.0.
Restrict the
staff.create and edit staff permission to only highly trusted staff members.
Use a reverse proxy or WAF to restrict access to the /api/admin/staff/permissions update endpoint to specific trusted roles.Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Fossbilling