CVE-2025-2610
בינונית 5.4
תיאור (מקור, אנגלית)
Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.
מדדים
- CVSS 3.1
-
5.4 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-20/9/2026
- CWE
- CWE-79
מוצרים מושפעים
magnussolution: magnusbilling
קישורים
- https://chocapikk.com/posts/2025/magnusbilling/ ExploitThird Party Advisory
- https://chocapikk.com/posts/2025/magnusbilling/ ExploitThird Party Advisory
- https://github.com/magnussolution/magnusbilling/commit/f0f083c76157e31149ae583…
- https://vulncheck.com/advisories/magnusbilling-alarm-xss Third Party Advisory