Executive brief
FOSSBilling, an open-source billing and client management platform, contains a security flaw in its mass mailing tool. An authorized administrator can use specially crafted filters to gain unauthorized access to the underlying database. This could lead to the theft of sensitive customer data, administrator password hashes, and system configuration details.
Technical details
A SQL injection vulnerability exists in the `Massmailer` module of FOSSBilling due to improper neutralization of user-supplied filters. In `src/modules/Massmailer/Service.php`, the `getMessageReceivers` function uses `sprintf` and `implode` to interpolate JSON-decoded filter values directly into a SQL query without parameterization. An authenticated attacker with administrator privileges can submit a crafted `message_update` API request containing SQL payloads in fields like `client_status`. When the administrator subsequently triggers a recipient preview or sends the message, the payload executes, allowing for full data exfiltration from the database. The issue is resolved in version 0.8.0.
Affected products
- FOSSBilling FOSSBilling 0.6.0 - 0.7.2
Timeline
- 2026-06-12: advisory: GitHub security advisory published
- 2026-07-06: disclosed: CVE published to NVD
- 2026-08-01: patched: Version 0.8.0 released to address the vulnerability