fossbilling是fossbilling团队开源的一种高效计费和客户管理方案。 FOSSBilling 0.8.0之前版本存在代码注入漏洞,该漏洞源于模板渲染系统存在服务器端模板注入漏洞,可能导致管理员注入任意Twig表达式,导致信息泄露和远程代码执行。
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| FOSSBilling | FOSSBilling | < 0.8.0 |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| FOSSBilling | FOSSBilling | < 0.8.0 | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | A Server-Side Template Injection (SSTI) vulnerability exists in FOSSBilling's template rendering system. Administrators with access to features that render Twig templates (email templates, mass mail campaigns, custom payment adapters, and the string_render API endpoint) can inject arbitrary Twig expressions, leading to information disclosure and remote code execution. The vulnerability exists because Twig templates are rendered without a sandbox, allowing access to the full Twig environment, API context, and the application's dependency injection container. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-28496.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2026-27604 | fossbilling 信息泄露漏洞 | |
| CVE-2026-23513 | FOSSBilling 授权问题漏洞 | |
| CVE-2025-64105 | FOSSBilling 授权问题漏洞 |
暂无评论