{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-108108/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:phpnuxbill:phpnuxbill:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-108107"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PHPNuxBill (\u003c= 2025.3.20)"],"_cs_severities":["critical"],"_cs_tags":["web-application","authentication-bypass","account-takeover","cve-2026-108108","phpnuxbill"],"_cs_type":"advisory","_cs_vendors":["PHPNuxBill"],"content_html":"\u003cp\u003ePHPNuxBill versions through 2025.3.20 contain a critical unauthenticated SQL injection vulnerability within the radius.php script. The vulnerability exists in the FreeRADIUS REST endpoint, where user-supplied parameters including username, macAddr, and nasid are passed directly into whereRaw() database queries without adequate sanitization. This flaw permits an unauthenticated attacker to execute arbitrary SQL commands against the backend database. By leveraging time-based blind SQL injection techniques, attackers can systematically infer database contents, including sensitive customer records and authentication credentials. This vulnerability represents a high risk to service providers using PHPNuxBill for RADIUS accounting and authentication, as it provides a direct vector for unauthorized data extraction.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote attackers to extract the entire customer database, including usernames, passwords, and billing information. This results in complete loss of confidentiality regarding subscriber data and potential compromise of downstream network access credentials managed by the RADIUS server.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and patching of all internet-facing instances of PHPNuxBill. Ensure all instances are updated beyond version 2025.3.20 to mitigate CVE-2026-108107.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAudit web server access logs for anomalous payloads containing SQL keywords (e.g., SLEEP, BENCHMARK, WAITFOR, or UNION SELECT) targeting the radius.php endpoint.\u003c/li\u003e\n\u003cli\u003eIf patching is not immediately feasible, restrict access to the radius.php endpoint at the network or web application firewall level to known-trusted RADIUS infrastructure IPs only.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-09T15:33:18Z","date_published":"2026-10-09T15:28:54Z","id":"https://feed.craftedsignal.io/briefs/2026-10-phpnuxbill-sqli/","summary":"PHPNuxBill versions through 2025.3.20 are vulnerable to an unauthenticated time-based blind SQL injection in the radius.php FreeRADIUS REST endpoint, allowing credential and data exfiltration.","title":"Unauthenticated SQL Injection in PHPNuxBill radius.php","url":"https://feed.craftedsignal.io/briefs/2026-10-phpnuxbill-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-108108","version":"https://jsonfeed.org/version/1.1"}