Impact
FOSSBilling versions older than 0.8.0 reveal the exact system version in the query string of every script and stylesheet tag that the Twig filters generate. This bypasses the hide_version_public setting and makes the version visible to anyone who can view any page, regardless of authentication. The exposed version information lowers the barrier for attackers to identify additional, possibly critical, vulnerabilities that apply to that specific release and to craft targeted exploits, thereby turning a normally protected setting into a reconnaissance aid.
Affected Systems
FOSSBilling products deployed with versions earlier than 0.8.0. All installations that have not applied the 0.8.0 release are impacted, because the asset cache buster parameters embedded in HTML output expose the version number.
Risk and Exploitability
The flaw has a CVSS score of 6.9, indicating medium severity. Because the information is publicly available to unauthenticated visitors, the attack vector is network‑based and does not require any special credentials. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers can use the disclosed version to search for known exploits and reduce the effort needed to pivot to other weaknesses, but the flaw itself does not provide direct code execution or privilege escalation capability.
OpenCVE Enrichment