CVE-2025-2609
HIGH EXPLOITED NUCLEIMagnusBilling Login Logs - Cross-Site Scripting
Title source: nucleiDescription
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.
Nuclei Templates (1)
MagnusBilling Login Logs - Cross-Site Scripting
HIGHVERIFIEDby DhiyaneshDK
Shodan:
html:"MagnusBilling"
FOFA:
body="MagnusBilling"
Scores
CVSS v3
8.2
EPSS
0.0552
EPSS Percentile
90.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Details
VulnCheck KEV
2025-03-21
CWE
CWE-79
Status
published
Products (1)
magnussolution/magnusbilling
< 7.3.0
Published
Mar 21, 2025
Tracked Since
Feb 18, 2026