CVE-2026-108109: PHPNuxBill through 2025.3.20 Account Takeover via Brute-Forceable Password Reset Code
PHPNuxBill through 2025.3.20 contains an account takeover vulnerability in the customer password reset flow in system/controllers/forgot.php that allows unauthenticated attackers to brute-force the 6-digit otpcode. Attackers knowing a customer username can guess the code without attempt limits or lockout, then read the newly set password from the HTTP response to hijack the account.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of PHPNuxBill through 2025.3.20 are affected where the customer password reset flow is accessible. An attacker needs to know a customer username; no authentication or user interaction is required.
What does an attacker need to do to take over an account?
The attacker can repeatedly guess the six-digit password-reset otp_code because the flow has no attempt limits or lockout. After a successful guess, the newly set password is included in the HTTP response, allowing the attacker to hijack the customer account.
Are default protections sufficient to prevent exploitation?
No. The affected reset flow lacks both attempt limits and lockout, so the reset code can be brute-forced remotely.