fossbilling是fossbilling团队开源的一种高效计费和客户管理方案。 fossbilling 0.5.4版本至0.8.0之前版本存在安全漏洞,该漏洞源于API角色处理中存在授权绕过,可能导致未经身份验证的攻击者访问特权 端点,无需有效凭据、会话或CSRF令牌即可调用管理员API方法。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| FOSSBilling | FOSSBilling | >= 0.5.4, < 0.8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| FOSSBilling | FOSSBilling | >= 0.5.4, < 0.8.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-28496 | FOSSBilling: Server-side template injection in Twig template rendering enables information | |
| CVE-2026-23513 | FOSSBilling: Broken Authorization in Client Transaction and Order Listings | |
| CVE-2025-64105 | FOSSBilling: IDOR Vulnerability in Support Ticket Creation |
No comments yet