Impact
FOSSBilling is an open‑source billing system. Versions 0.6.0 through 0.7.2 contain an SQL injection flaw in the Massmailer module’s recipient‑filter logic. An authenticated administrator can feed crafted filter values when updating a mass‑email message, causing the untrusted input to be directly interpolated into the recipient‑selection SQL query. This allows the attacker to execute arbitrary SQL, exposing, altering, or deleting database data and compromising the confidentiality, integrity, and availability of the billing platform.
Affected Systems
The issue affects FOSSBilling deployments using releases 0.6.0, 0.6.1, 0.6.2, 0.7.0, 0.7.1, and 0.7.2. The vendor patch is included in version 0.8.0. Administrators should verify the current version and plan an upgrade if their installation is running within the affected range.
Risk and Exploitability
The CVSS score is moderate (6.9) and the EPSS score is less than 1 %, indicating a very low but non‑zero probability of real‑world exploitation. The flaw requires authenticated administrator access, so the likely attack vector is a compromised or insider administrator account or an attacker who has obtained credentials. Although exploitation is not trivial, the Massmailer module can be a high‑value target for attackers seeking to manipulate billing data or deploy malicious code. The vulnerability is not listed in the CISA KEV catalog, but its potential impact makes prompt patching or mitigation advisable.
OpenCVE Enrichment