Junglewise Threat Intelligence

CVE-2026-43924: FOSSBilling open redirect in Redirect module

CVE-2026-43924 · Severity: info · CVSS 4.8 · Published 2026-06-03

Technologies: FOSSBilling. Vendors: FOSSBilling.

Executive brief

FOSSBilling is an open-source billing and client management platform. A vulnerability in its Redirect module allows administrators to configure redirects to untrusted external websites. This could be used in phishing campaigns to trick customers into visiting malicious sites while appearing to follow a legitimate link from their billing provider.

Technical details

An open redirect vulnerability exists in the FOSSBilling Redirect module due to insufficient validation of URL schemes in administrator-configured destination URLs. The system only applies basic sanitization (htmlspecialchars and trim) before storing targets in the database and issuing 301 redirects via the Location header. An attacker with administrative privileges can configure arbitrary external URLs as redirect targets. Because the application issues a 301 (Moved Permanently) response, browsers may cache the malicious redirect persistently. This issue is resolved in version 0.8.0.

Affected products

  • FOSSBilling FOSSBilling < 0.8.0

Timeline

  • 2026-05-28: patched: Version 0.8.0 released
  • 2026-05-30: advisory: GitHub Security Advisory published
  • 2026-06-03: disclosed: CVE published to NVD

References

Related threats