CVE-2025-52289
HIGHMagnussolution Magnusbilling - Improper Access Control
Title source: ruleDescription
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
Exploits (2)
Scores
CVSS v3
8.0
EPSS
0.0005
EPSS Percentile
14.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-284
CWE-269
Status
published
Affected Products (1)
magnussolution/magnusbilling
Timeline
Published
Jul 31, 2025
Tracked Since
Feb 18, 2026