CVE-2025-2609
MagnusBilling Stored Cross-Site Scripting in Login Logs
Record summary
CVE-2025-2609 has a selected CVSS score of 8.2 (high); EIP currently links 1 Nuclei template.
Description
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 21, 2025 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
MagnusBillingBrowse MagnusSolution / MagnusBillingDefault status: affected | CVE List, VulnCheck | Through 7.3.0 | affected |
Nuclei templates
1ProjectDiscoveryHIGHMagnusBilling Login Logs - Cross-Site ScriptingCVSS 8.2
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.This issue affects MagnusBilling- through 7.3.0.
Impact
Unauthenticated attackers can inject malicious HTML and JavaScript into login logs that persist and execute when administrators view the log component, potentially leading to session hijacking and privilege escalation.
Remediation
Upgrade to MagnusBilling version 7.3.1 or later that properly sanitizes input in the login logging component.
Source: ProjectDiscovery