CVE-2026-108109 PUBLISHED

PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code

Assigner: VulnCheck
Reserved: 09.10.2026 Published: 09.10.2026 Updated: 09.10.2026

PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor hotspotbilling
Product phpnuxbill
Versions Default: unaffected
  • affected from 0 to 2025.3.20 (incl.)

Credits

  • tonghuaroot finder
  • leediay153 from Viettel Post reporter

References

Problem Types

  • Improper Restriction of Excessive Authentication Attempts CWE