PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 09 Oct 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account. | |
| Title | PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-10-09T14:33:32.201Z
Reserved: 2026-10-09T13:44:40.883Z
Link: CVE-2026-108109
No data.
Status : Received
Published: 2026-10-09T15:17:12.047
Modified: 2026-10-09T15:17:12.047
Link: CVE-2026-108109
No data.
OpenCVE Enrichment
Updated: 2026-10-09T15:30:08Z
Weaknesses