Executive brief
FOSSBilling is an open-source platform used by businesses to manage client billing and automated services. A security flaw allows a registered customer to view the private service details and personal information of other customers by guessing order numbers. This could lead to the exposure of sensitive data, including names, addresses, phone numbers, and service configurations, potentially damaging a company's reputation and violating data privacy regulations.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability exists in the `__call` method of the `Servicecustom` Client API. The root cause is located in `src/modules/Servicecustom/Service.php` within the `getServiceCustomByOrderId()` function, which fetches order data using `getExistingModelById` without verifying that the `client_id` associated with the order matches the authenticated user. Because order IDs are sequential, an authenticated attacker can iterate through IDs to retrieve cross-client data. This exposure includes PII such as names, emails, addresses, and VAT numbers, as well as specific service configurations. The issue is addressed in version 0.8.0 by implementing proper ownership validation.
Affected products
- FOSSBilling FOSSBilling <= 0.7.2
Timeline
- 2026-05-28: patched: Version 0.8.0 released
- 2026-06-12: advisory: GitHub Security Advisory published
- 2026-06-24: disclosed: CVE published to NVD