VYPR
High severity8.2NVD Advisory· Published Mar 21, 2025· Updated Aug 28, 2026

CVE-2025-2609

CVE-2025-2609

Description

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:*range: <=7.3.0
    • (no CPE)range: <=7.3.0
    • (no CPE)range: 0

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.