Impact
FOSSBilling is a free, open‑source billing and client management system. In versions 0.5.6 through 0.7.2, when the 'Require Email Confirmation' setting is enabled, a logged‑in client with an unverified email address (email_approved = 0) can access all client‑area pages (e.g. /client/balance, /client/order/list, /client/invoice) and read real account data, including wallet balances and transaction history. The API‑side enforcement correctly restricts unverified clients to only profile‑related endpoints, but the page‑side enforcement is overly permissive, allowing any request whose path starts with /client. Version 0.8.0 contains a fix. No known workarounds that don't involve modifying the source code are available.
Affected Systems
The vulnerability affects the FOSSBilling billing and client management system. All releases from 0.5.6 up to and including 0.7.2 are impacted, and the issue is resolved in version 0.8.0 and later. No other vendors or ancillary products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 classifies this as a moderate‑risk vulnerability. The EPSS score is reported as less than 1 %, and the flaw is not contained in the CISA KEV catalog, indicating no known in‑the‑wild exploitation reports. Based on the description, it is inferred that the exploitability is high for any logged‑in client that has an unverified email address, as the attacker only needs to request any /client page to view sensitive data.
OpenCVE Enrichment