Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection. | |
| Title | PHPNuxBill through 2025.3.20 Unauthenticated SQL Injection via radius.php | |
| Weaknesses | CWE-89 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T14:46:56.077Z
Reserved: 2026-10-09T13:44:40.883Z
Link: CVE-2026-108107
Updated: 2026-10-09T14:46:23.126Z
Status : Deferred
Published: 2026-10-09T15:17:11.713
Modified: 2026-10-09T16:45:01.980
Link: CVE-2026-108107
No data.
OpenCVE Enrichment
Updated: 2026-10-09T15:30:08Z