Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.
This issue affects MagnusBilling: through 7.3.0.
Metrics
Affected Vendors & Products
References
History
Tue, 01 Apr 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Magnussolution
Magnussolution magnusbilling |
|
CPEs | cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:* | |
Vendors & Products |
Magnussolution
Magnussolution magnusbilling |
Tue, 25 Mar 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 21 Mar 2025 23:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0. | |
Title | MagnusBilling Stored Cross-Site Scripting in Login Logs | |
Weaknesses | CWE-79 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2025-03-25T15:11:25.188Z
Reserved: 2025-03-21T14:47:10.303Z
Link: CVE-2025-2609

Updated: 2025-03-25T15:11:19.018Z

Status : Analyzed
Published: 2025-03-21T23:15:21.493
Modified: 2025-04-01T20:28:29.337
Link: CVE-2025-2609

No data.