Security: hotspotbilling/phpnuxbill
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Unauthenticated account takeover via weak-random reset OTP and password-reset verification with no rate limiting/lockoutGHSA-337r-rrrc-r559 published
Aug 6, 2026 by ibnuxHigh -
Unauthenticated SQL Injection in radius.php Allows Time‑Based Blind Database QueryingGHSA-q8ch-r8cv-q579 published
Aug 6, 2026 by ibnuxCritical -
CHAP Authentication Bypass in radius.php Due to Inverted Comparison LogicGHSA-6f62-x25v-9686 published
Aug 6, 2026 by ibnuxCritical -
[Security] Authenticated RCE via Unrestricted File Upload in Plugin ManagerGHSA-rv83-2vv6-585q published
Aug 6, 2026 by ibnuxCritical
Learn more about advisories related to hotspotbilling/phpnuxbill in the GitHub Advisory Database