← Back to CVE List
CVE-2026-108109NVD
Vulnerability Summary
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
CVSS v4.0 Base Metrics — Score 9.3 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Attack RequirementsNone
Privileges RequiredNone
User InteractionNone
Confidentiality (Vulnerable System)High
Integrity (Vulnerable System)High
Availability (Vulnerable System)None
Confidentiality (Subsequent System)None
Integrity (Subsequent System)None
Availability (Subsequent System)None
CVSS v3.1 Base Metrics — Score 9.1 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- hotspotbilling phpnuxbill <= 2025.3.20
- hotspotbilling phpnuxbill 2025.3.20
External References
- https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-337r-rrrc-r559
- https://github.com/hotspotbilling/phpnuxbill/commit/c3c2a92d468af91136d747b75142ed72f10320cc
- https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/system/controllers/forgot.php#L41
- https://github.com/hotspotbilling/phpnuxbill
- https://www.vulncheck.com/advisories/phpnuxbill-through-2025.3.20-account-takeover-via-brute-forceable-password-reset-code