<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>PHPNuxBill (&lt;= 2025.3.20) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/phpnuxbill--2025.3.20/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 15:28:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/phpnuxbill--2025.3.20/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated SQL Injection in PHPNuxBill radius.php</title><link>https://feed.craftedsignal.io/briefs/2026-10-phpnuxbill-sqli/</link><pubDate>Fri, 09 Oct 2026 15:28:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-phpnuxbill-sqli/</guid><description>PHPNuxBill versions through 2025.3.20 are vulnerable to an unauthenticated time-based blind SQL injection in the radius.php FreeRADIUS REST endpoint, allowing credential and data exfiltration.</description><content:encoded><![CDATA[<p>PHPNuxBill versions through 2025.3.20 contain a critical unauthenticated SQL injection vulnerability within the radius.php script. The vulnerability exists in the FreeRADIUS REST endpoint, where user-supplied parameters including username, macAddr, and nasid are passed directly into whereRaw() database queries without adequate sanitization. This flaw permits an unauthenticated attacker to execute arbitrary SQL commands against the backend database. By leveraging time-based blind SQL injection techniques, attackers can systematically infer database contents, including sensitive customer records and authentication credentials. This vulnerability represents a high risk to service providers using PHPNuxBill for RADIUS accounting and authentication, as it provides a direct vector for unauthorized data extraction.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated remote attackers to extract the entire customer database, including usernames, passwords, and billing information. This results in complete loss of confidentiality regarding subscriber data and potential compromise of downstream network access credentials managed by the RADIUS server.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the identification and patching of all internet-facing instances of PHPNuxBill. Ensure all instances are updated beyond version 2025.3.20 to mitigate CVE-2026-108107.</p>
<ul>
<li>Audit web server access logs for anomalous payloads containing SQL keywords (e.g., SLEEP, BENCHMARK, WAITFOR, or UNION SELECT) targeting the radius.php endpoint.</li>
<li>If patching is not immediately feasible, restrict access to the radius.php endpoint at the network or web application firewall level to known-trusted RADIUS infrastructure IPs only.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>web-application</category><category>authentication-bypass</category><category>account-takeover</category><category>cve-2026-108108</category><category>phpnuxbill</category></item></channel></rss>