An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field
Metrics
Affected Vendors & Products
References
History
Tue, 14 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Unvalidated CSV Registration in HostBill | |
| Weaknesses | CWE-269 CWE-730 |
Tue, 14 Apr 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hostbillapp
Hostbillapp hostbill |
|
| Vendors & Products |
Hostbillapp
Hostbillapp hostbill |
Tue, 14 Apr 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Hostbill v.2025-11-24 and 2025-12-01 allows a remote attacker to execute arbitrary code and escalate privileges via the CSV registration field | |
| References |
|
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-14T13:28:53.517Z
Reserved: 2026-03-09T00:00:00.000Z
Link: CVE-2026-31049
No data.
Status : Received
Published: 2026-04-14T14:16:13.130
Modified: 2026-04-14T14:16:13.130
Link: CVE-2026-31049
No data.
OpenCVE Enrichment
Updated: 2026-04-14T16:32:00Z