Impact
FOSSBilling is a free, open‑source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in the client self‑registration endpoint allows any visitor to assign themselves to an arbitrary client group during sign‑up. Because client groups can gate promo code eligibility, an attacker may apply group‑restricted discount codes and receive unauthorized discounts. Version 0.8.0 contains a patch. As a workaround, administrators can either remove group restrictions from promo codes or disable client self‑registration (Settings → Clients → Disable signup).
Affected Systems
FOSSBilling, all versions prior to 0.8.0.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity, and based on the description, it is inferred that the vulnerability can be triggered over HTTP without authentication. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Since the flaw is in a public‑facing registration endpoint, attackers can exploit it from anywhere without prior access.
OpenCVE Enrichment