Impact
FOSSBilling is a free, open‑source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the Massmailer module filter functionality. An authenticated administrator can supply crafted filter values when updating a mass‑email message, causing untrusted input to be interpolated directly into SQL in the recipient selection query. This allows an attacker to execute arbitrary SQL, potentially exposing, altering, or deleting database data and compromising the confidentiality, integrity, and availability of the billing platform. The vendor addressed the issue in version 0.8.0, and several workarounds are available.
Affected Systems
The issue affects FOSSBilling deployments using releases 0.6.0, 0.6.1, 0.6.2, 0.7.0, 0.7.1, and 0.7.2. The vendor patch is included in version 0.8.0. Administrators should verify the current version and plan an upgrade if their installation is running within the affected range.
Risk and Exploitability
The CVSS score is moderate (6.9) and the EPSS score is less than 1 %, indicating a very low but non‑zero probability of real‑world exploitation. The flaw requires authenticated administrator access, so the likely attack vector is a compromised or insider administrator account or an attacker who has obtained credentials. Although exploitation is not trivial, the Massmailer module can be a high‑value target for attackers seeking to manipulate billing data. The vulnerability is not listed in the CISA KEV catalog, but its potential impact makes prompt patching or mitigation advisable.
OpenCVE Enrichment