Unrated severityNVD Advisory· Published Jul 31, 2025· Updated Jul 31, 2025
CVE-2025-52289
CVE-2025-52289
Description
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
Affected products
2- MagnusBilling/MagnusBillingdescription
- Range: = 7.8.5.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.