Impact
FOSSBilling is a free, open‑source billing and client‑management system. Versions prior to 0.8.0 allow a staff member who only has the staff.create_and_edit_staff permission to call the admin API endpoint /api/admin/staff/permissions_update on their own account and grant themselves arbitrary module permissions, bypassing the intended role‑based access control boundary. This results in persistent privilege escalation.
Affected Systems
The vulnerability affects all installations of FOSSBilling running before version 0.8.0. The issue has been fixed in version 0.8.0 and later.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. The EPSS score of less than 1% reflects a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires authenticated access to the admin API and possession of the staff.create_and_edit_staff permission; with that privilege the attacker can modify permissions permanently.
OpenCVE Enrichment