An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unvalidated CSV Registration in HostBill | |
| Weaknesses | CWE-269 CWE-730 |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hostbillapp
Hostbillapp hostbill |
|
| Vendors & Products |
Hostbillapp
Hostbillapp hostbill |
Tue, 14 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field | |
| References |
|
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T13:28:53.517Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31049
No data.
Status : Received
Published: 2026-04-14T14:16:13.130
Modified: 2026-04-14T14:16:13.130
Link: CVE-2026-31049
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:32:00Z