FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a ClientPasswordReset record already exists for a client (from a previous unexpired reset request), subsequent calls to the reset_password guest API endpoint reuse the existing token instead of generating a new one. The 15-minute validity window is anchored to the first request's created_at timestamp, not the time of the most recent email. An attacker who obtained the original reset link remains able to use it even after the victim requests a new reset, because the original token is never invalidated or rotated. Version 0.8.0 patches the issue. Some workarounds are available. Configure a reverse proxy (e.g., Nginx, Apache, Cloudflare) to apply per-IP rate limiting to the /client/reset-password endpoint to minimize the window of opportunity, and/or manually clear expired client_password_reset records from the database after a client reports a suspected compromise.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Repository is a small standalone Python PoC named FOSKiller for two FOSSBilling vulnerabilities affecting versions up to 0.7.2. Structure is minimal: one main script (fossbilling_poc.py), a README with vulnerability and usage documentation, requirements.txt, and .gitignore. The Python script is the operational entry point and includes dependency bootstrapping, colored console output, HTTP session creation with optional proxy support, version detection/range checking, per-CVE execution paths, summary reporting, optional JSON output saving, and exit codes based on vulnerability findings. Main exploit capabilities: 1) CVE-2026-53647: tests/exploits unauthenticated disclosure of service API key configuration via the guest API endpoint /api/guest/serviceapikey/get_info. README states this can expose custom fields, API credentials, hostnames, and passwords when a valid API key is supplied. 2) CVE-2026-53646: tests/exercises password reset token reuse by interacting with guest password reset endpoints. The documented chain is repeated reset issuance followed by reuse of an older token to set a chosen password, enabling potential persistent account takeover. The exploit is not framework-based and is more than a detector: it contains active exploitation logic for both issues, though it remains a PoC rather than a generalized weaponized toolkit. It uses Python requests with TLS verification disabled (verify=False), supports operator-supplied target URL, API key, email, timeout, proxy, output file, check-only mode, exploit mode, and force mode. No hardcoded victim infrastructure, C2, or malware behavior is present; all network interaction is directed at the user-specified FOSSBilling target and its guest API endpoints.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.