CVE-2025-2609 is a cross-site scripting (XSS) vulnerability in MagnusSolution MagnusBilling versions through 7.3.0. It allows unauthenticated attackers to inject and store malicious HTML content within the login log component, which is viewable at /mbilling/index.php/logUsers/read. The vulnerability has a CVSS score of 6.1 (Medium), indicating it can be exploited remotely with low complexity, requiring user interaction, and potentially leading to low impact on confidentiality and integrity. While there is no evidence of active exploitation or Metasploit modules, Nuclei templates exist, and it has garnered significant community discussion, suggesting potential interest from attackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.3.0CPE matchmatch criteria | cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:* | ||
>= 0, <= 7.3.0CPE match | cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.