Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 09 Oct 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 09 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account. | |
| Title | PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T17:26:03.792Z
Reserved: 2026-10-09T13:44:40.883Z
Link: CVE-2026-108109
Updated: 2026-10-09T17:25:52.541Z
Status : Deferred
Published: 2026-10-09T15:17:12.047
Modified: 2026-10-09T18:17:06.727
Link: CVE-2026-108109
No data.
OpenCVE Enrichment
Updated: 2026-10-09T15:30:08Z