Executive brief
FOSSBilling is an open-source platform used by businesses to manage client billing, orders, and support. A security flaw in the system's search filters allowed registered customers to bypass privacy protections and view the private transaction and order data of other clients. This could lead to the exposure of sensitive financial information, including payment amounts, order statuses, and timestamps.
Technical details
An authorization bypass vulnerability exists in FOSSBilling versions 0.7.2 and prior due to incorrect SQL query construction in the ServiceTransaction::getSearchQuery() and Order\Service::getSearchQuery() methods. Specifically, OR-based search and action filters were appended to SQL queries without proper grouping (parentheses). Because of SQL operator precedence, these OR clauses could be evaluated independently of the mandatory client_id constraint. An authenticated attacker can exploit this by sending crafted requests to the 'client/invoice/transaction_get_list' or 'client/order/get_list' API endpoints to retrieve records belonging to other tenants. The issue is fixed in version 0.8.0 by implementing correct logical grouping in WHERE clauses.
Affected products
- FOSSBilling FOSSBilling <= 0.7.2
Timeline
- 2026-05-28: patched: Version 0.8.0 released
- 2026-06-12: advisory: GitHub Security Advisory published
- 2026-06-23: disclosed: CVE published to NVD