← back
CVE-2025-2609highobserved exploitationCWE-79

MagnusBilling Stored Cross-Site Scripting in Login Logs

58Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 8.2epss 1.1%
from disclosure to weapon
Published on NVDMar 21
VulnCheckMar 21
exploitation probability
1.1%top 38% of all CVEs
observed exploitation
yesVulnCheck
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N