PT-2026-56043 · Unknown · Fossbilling
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FOSSBilling versions prior to 0.8.1
Description
Downloadable product files are stored using a deterministic path derived from the filename. When an administrator uploads a file, the system stores it as
md5(<original filename>) within the uploads directory. Since the path depends solely on the client-supplied filename, multiple products or order files uploaded with the same original filename will resolve to the same storage path. Consequently, a subsequent upload can overwrite a previous one, leading customers or administrators to download the incorrect file.Recommendations
Update to version 0.8.1.
Restrict the
servicedownloadable.manage permission to fully trusted administrators only.
Ensure downloadable product files use unique filenames before upload to reduce accidental collisions.Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Fossbilling