URL has been copied successfully!
FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE

A critical server-side template injection (SSTI) vulnerability in FOSSBilling, tracked as CVE-2026-28496, is exposing instances to potential full database compromise and remote code execution (RCE), with early signs of active exploitation appearing shortly after public disclosure. This flaw is documented under GitHub advisory GHSA-57mv-jm88-66jc and affects all versions up to 0.7.2. It has been patched […] The post FOSSBilling Flaw Lets Admin Attackers Abuse DI Container for SQL Access and RCE appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/fossbilling-flaw-lets-admin-attackers-abuse-di-container/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link