CVE-2025-2610

Executive Summary

CVE-2025-2610: Improper neutralization of input during web page generation in MagnusSolution MagnusBilling (Alarm Module) allows authenticated users to inject stored cross‑site scripting via protected/components/MagnusLog.Php. Affected versions up to 7.3.0. Exploit requires valid credentials; attacker can execute arbitrary JavaScript in victims’ browsers, leading to session hijacking, data theft, or defacement. No KEV listing yet.


Authoritative CVE Metadata - CVSS Base Score: 7.6 (HIGH) - Published: 2025-03-21T23:15:21.613 - Last Modified: 2026-08-28T16:16:50.513

Original Description: Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

"True silence is the rest of the mind; it is to the spirit what sleep is to the body, nourishment and refreshment."

— William Penn
Source: NVD