漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
FOSSBilling: IDOR in Servicecustom Client API allows cross-client data access
Vulnerability Description
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associated order without verifying the authenticated client owns it, potentially exposing cross-client data through IDOR. An authenticated client can access any other client's custom service by guessing sequential order IDs. This can lead to a confidentiality breach — attackers can read client PII (name, email, phone, address, company details, VAT number) and service configuration data belonging to other clients. This issue has been fixed in version 0.8.0.
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Vulnerability Type
访问控制不恰当
Vulnerability Title
FOSSBilling 权限许可和访问控制问题漏洞
Vulnerability Description
fossbilling是fossbilling团队开源的一种高效计费和客户管理方案。 FOSSBilling 存在安全漏洞,该漏洞源于Servicecustom Client API的__call方法未验证认证客户端是否拥有所获取的订单,可能通过IDOR导致跨客户端数据泄露。认证客户端可通过猜测连续订单ID访问其他客户的自定义服务,导致读取客户的服务配置数据。
CVSS Information
N/A
Vulnerability Type
N/A