PT-2026-56042 · Unknown · Fossbilling
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions 0.5.3 through 0.7.2
Description
The Guest
serviceapikey/get info API endpoint is accessible without authentication. An attacker with a valid API key can retrieve all custom configuration parameters, specifically the custom * fields, stored in the database record associated with that key. These fields are managed by administrators and may contain sensitive business information, including pricing tiers, feature flags, rate limits, expiry overrides, or access scope data.Recommendations
Update to version 0.8.0.
Avoid storing sensitive data in
custom * API key configuration fields.
Monitor API logs for suspicious calls to the /api/guest/serviceapikey/get info endpoint.
Disable the Serviceapikey module if it is not in active use.Exploit
Fix
Information Disclosure
Missing Authorization
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling