PT-2026-46062 · Unknown · Fossbilling

·

CVE-2026-43924

·

Published

2026-06-03

·

Updated

2026-06-04

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions FOSSBilling versions prior to 0.8.0
Description The Redirect module fails to validate the URL scheme of destination URLs configured by administrators before they are stored or issued. This allows the configuration of arbitrary external URLs as redirect targets, enabling open redirects that can be used in phishing attacks. When a user follows a legitimate URL, they may be silently redirected to an external site controlled by an attacker via a 301 (Moved Permanently) response, which is persistently cached by browsers. Exploitation requires administrator privileges to create or modify redirect entries.
Recommendations Update to version 0.8.0. Restrict admin access to the Redirect module to trusted administrators only. Audit existing redirect entries in the extension meta table where extension is set to mod redirect for unexpected or external target URLs.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-43924
GHSA-V8RF-G37V-VGPX

Affected Products

Fossbilling