Executive brief
FOSSBilling is an open-source platform used by businesses to manage client billing and automated invoicing. A security flaw in the system's guest interface allows unauthorized individuals to modify unpaid invoices if they obtain a specific web link or invoice ID. While an attacker cannot redirect payments to their own personal bank account unless they have already compromised the system's settings, they can disrupt business operations by changing which approved payment method is used for a transaction.
Technical details
The vulnerability is caused by a missing authorization check (`checkInvoiceAuth()`) in the `invoice/update` and `invoice/payment` endpoints within the Guest API (`src/modules/Invoice/Api/Guest.php`). An unauthenticated attacker who obtains a valid invoice hash—potentially leaked via referrer headers, shared URLs, or emails—can send a POST request to modify the `gateway_id` of an unpaid invoice. Additionally, the `payment` endpoint can be used to access payment adapter HTML output, potentially exposing sensitive transaction details. The exploit is limited to gateways already configured in the system by an administrator. The issue is addressed in version 0.8.0.
Affected products
- FOSSBilling FOSSBilling < 0.8.0
Timeline
- 2026-06-20: advisory: GitHub security advisory published
- 2026-07-06: disclosed: NVD publication date