fossbilling是fossbilling团队开源的一种高效计费和客户管理方案。 FOSSBilling 0.6.21版本至0.7.2版本存在授权问题漏洞,该漏洞源于工单创建流程未验证订单所有权,可能导致通过构造请求将工单关联至其他客户的订单,影响完整性和机密性。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FOSSBilling | FOSSBilling | >= 0.6.21, < 0.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FOSSBilling | FOSSBilling | >= 0.6.21, < 0.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-27604 | FOSSBilling: Improper API Role Validation (system) Enables Unauthenticated Access to Privi | |
| CVE-2026-28496 | FOSSBilling: Server-side template injection in Twig template rendering enables information | |
| CVE-2026-23513 | FOSSBilling: Broken Authorization in Client Transaction and Order Listings |
No comments yet