Impact
FOSSBilling is a free, open‑source billing and client‑management system. Versions 0.6.0 through 0.7.2 contain a stored cross‑site scripting vulnerability in the client‑facing email history views. Email HTML content (`content_html`) is rendered into a JavaScript template literal using the `|raw` filter, bypassing all output escaping. An attacker with admin access can inject malicious JavaScript payloads into the email content that execute in the browsers of any clients who view the compromised email history. Version 0.8.0 contains a vendor fix. Workarounds include restricting admin account access, auditing email content for suspicious payloads, and monitoring client accounts for unusual activity.
Affected Systems
The affected system is the FOSSBilling billing and client‑management platform. All releases from version 0.6.0 up to and including 0.7.2 are vulnerable. Version 0.8.0 contains the vendor fix.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity. The exploitation requires administrator privileges, limiting the attack surface to compromised or weak admin accounts. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalogue. In the event of exploitation, the malicious JavaScript would run within the browsers of clients who view the compromised email history, potentially compromising client‑side trust.
OpenCVE Enrichment