Record summary

CVE-2025-2610 has a selected CVSS score of 7.6 (high); EIP currently links 1 Nuclei template.

Description

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Mar 21, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 25, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

CVE List, VulnCheckThrough 7.3.0affected

Nuclei templates

1
ProjectDiscoveryHIGHMagnusBilling Alarm Module - Cross-Site ScriptingCVSS 7.6

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.This issue affects MagnusBilling- through 7.3.0.

Impact

Authenticated attackers can inject malicious HTML and JavaScript through the alarm module that persists and executes when other administrators view alarm configurations, potentially leading to session hijacking and privilege escalation.

Remediation

Upgrade to MagnusBilling version 7.3.1 or later that properly sanitizes input in the alarm module.

WeaknessesCWE-79
AuthorsDhiyaneshDK
Template tagscvecve2025mbillingxssmagnusbillingauthenticatedvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N
CPE: cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:*
Shodan: http.html:"magnusbilling"
FOFA: body="magnusbilling"

Source: ProjectDiscovery

References

4