Executive brief
FOSSBilling, an open-source billing and client management platform, contains a flaw in its user registration process. An attacker can exploit this to assign themselves to restricted customer groups, such as 'Staff' or 'Resellers', without authorization. This allows the attacker to use exclusive discount codes and obtain services at unauthorized lower prices, potentially leading to financial loss for the service provider.
Technical details
A mass assignment vulnerability exists in the guestCreateClient() handler within src/modules/Client/Service.php. The application fails to filter the input data before passing it to the internal createClient() method, which unconditionally assigns the 'group_id' parameter to the new user record. An unauthenticated attacker can exploit this by including a 'group_id' field in their POST request to the /api/guest/client/create endpoint. By joining a privileged group, the attacker bypasses eligibility checks in the promo code system, enabling the use of restricted discounts. This issue is resolved in version 0.8.0.
Affected products
- FOSSBilling FOSSBilling 0.1.0 to 0.7.2
Timeline
- 2026-06-04: advisory: GitHub Security Advisory published
- 2026-07-06: disclosed: NVD publication date