Tag
PHPNuxBill versions through 2025.3.20 are vulnerable to an unauthenticated time-based blind SQL injection in the radius.php FreeRADIUS REST endpoint, allowing credential and data exfiltration.