CVE-2025-2610
HIGH EXPLOITED NUCLEIMagnusBilling Alarm Module - Cross-Site Scripting
Title source: nucleiDescription
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.
Nuclei Templates (1)
MagnusBilling Alarm Module - Cross-Site Scripting
HIGHVERIFIEDby DhiyaneshDK
Shodan:
http.html:"magnusbilling"
FOFA:
body="magnusbilling"
Scores
CVSS v3
7.6
EPSS
0.0229
EPSS Percentile
84.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
Details
VulnCheck KEV
2025-03-21
CWE
CWE-79
Status
published
Products (1)
magnussolution/magnusbilling
< 7.3.0
Published
Mar 21, 2025
Tracked Since
Feb 18, 2026