---
id: CVE-2026-108107
title: >-
  PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection
  vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates
  request parameters into whereRaw() queries
summary: >-
  PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection
  vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates
  request parameters into whereRaw() queries. Attackers can send crafted
  username, macAddr or…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-89
published: '2026-10-09'
updated: '2026-10-09'
sourceUpdated: '2026-10-09T16:45:01.980'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-108107'
references:
  - url: 'https://github.com/hotspotbilling/phpnuxbill'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/hotspotbilling/phpnuxbill/blob/2025.3.13/radius.php#L277
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-q8ch-r8cv-q579
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/phpnuxbill-through-2025.3.20-unauthenticated-sql-injection-via-radius-php
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/hotspotbilling/phpnuxbill/security/advisories/GHSA-q8ch-r8cv-q579
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
ingestedAt: '2026-10-09T16:02:33.384Z'
---

## Overview

PHPNuxBill through 2025.3.20 contains an unauthenticated SQL injection vulnerability in the radius.php FreeRADIUS REST endpoint that interpolates request parameters into whereRaw() queries. Attackers can send crafted username, macAddr or nasid parameters to the accounting or authenticate actions to extract customer records and credentials via time-based blind SQL injection.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
