Account Takeover Vulnerability in PHPNuxBill by HotSpot Billing
CVE-2026-108109
9.3CRITICAL
What is CVE-2026-108109?
PHPNuxBill versions up to 2025.3.20 contain a significant vulnerability in the password reset process, specifically within the 'forgot' controller. This flaw allows attackers to attempt unlimited guesses on the 6-digit OTP code, provided they know the username of a targeted customer. Since there are no restrictions on the number of attempts, attackers can eventually discover the OTP and hijack the associated account by intercepting the response which reveals the newly set password.
Affected Version(s)
phpnuxbill 0 <= 2025.3.20
References
CVSS V4
Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
tonghuaroot
leediay153 from Viettel Post
