HostBill Arbitrary Code Execution and Privilege Escalation Vulnerability

Vulnerability

A vulnerability in HostBill versions through 2025-11-24 and 2025-12-01 allows remote attackers to execute arbitrary code and escalate privileges. This issue arises from a lack of proper server-side validation in the admin panel, particularly in the client import feature that accepts CSV files. Administrators can bypass mandatory registration field requirements, leading to the creation of invalid or incomplete client records. Additionally, the vulnerability can be exploited by manipulating registration field configuration requests to modify or bypass restrictions on essential fields such as username, email, and password.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the server and allow attackers to gain elevated privileges, potentially compromising the entire application and its data.

Reproduction

The vulnerability can be reproduced by logging into the HostBill admin panel and navigating to 'Manage Clients' -> 'Import Clients (CSV)'. After uploading a CSV file with invalid or missing values, such as an empty email or a weak password, the application will create client records without any validation errors. Alternatively, the vulnerability can be exploited by intercepting and modifying requests related to registration field management to bypass restrictions on mandatory fields.

Remediation

Users are advised to update HostBill to the latest version, available through the Microsoft Update Catalog.

Added: Apr 14, 2026, 2:21 PM
Updated: Apr 14, 2026, 2:21 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
6.3
remediation
7.7
relevance
5.9
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.