CVE-2025-2609
Executive Summary
CVE-2025-2609 exposes an XSS flaw in MagnusBilling (up to 7.3.0) where unauthenticated users can inject arbitrary HTML into the log view at /mbilling/index.php/logUsers/read via the MagnusLog.Php component. This allows attackers to execute scripts in the victim’s browser, potentially leading to session hijacking, data theft, or defacement. The vulnerability is not listed in CISA KEV.
Authoritative CVE Metadata - CVSS Base Score: 8.2 (HIGH) - Published: 2025-03-21T23:15:21.493 - Last Modified: 2026-08-28T16:16:50.357
Original Description: Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.
This issue affects MagnusBilling: through 7.3.0.
"Never doubt that a small group of thoughtful, committed people can change the world. Indeed. It is the only thing that ever has."
— Margaret Mead