Unauthenticated SQL Injection in PHPNuxBill by Hotspotbilling
CVE-2026-108107

9.3CRITICAL

Key Information:

Vendor
CVE Published:
9 October 2026

What is CVE-2026-108107?

An unauthenticated SQL injection vulnerability exists in PHPNuxBill version 2025.3.20 and earlier, specifically in the radius.php FreeRADIUS REST endpoint. This vulnerability allows attackers to manipulate crafted username, macAddr, or nasid parameters in requests sent to the accounting or authenticate actions. By leveraging this weakness, malicious users can perform time-based blind SQL injection attacks, potentially accessing sensitive customer records and credentials.

Affected Version(s)

phpnuxbill 0 <= 2025.3.20

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

kitu232
leediay153 from Viettel Post
.