Unauthenticated SQL Injection in PHPNuxBill by Hotspotbilling
CVE-2026-108107
9.3CRITICAL
What is CVE-2026-108107?
An unauthenticated SQL injection vulnerability exists in PHPNuxBill version 2025.3.20 and earlier, specifically in the radius.php FreeRADIUS REST endpoint. This vulnerability allows attackers to manipulate crafted username, macAddr, or nasid parameters in requests sent to the accounting or authenticate actions. By leveraging this weakness, malicious users can perform time-based blind SQL injection attacks, potentially accessing sensitive customer records and credentials.
Affected Version(s)
phpnuxbill 0 <= 2025.3.20
