CVE-2026-108109
EUVD-2026-9581009.10.2026, 15:17
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otp_code. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.
References