Sploitus

CVE-2025-52289

1 known exploit for CVE-2025-52289

A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.

Affected products
Magnusbilling
Magnussolution Magnusbilling
= 7.8.5.3
Fix
Available
CVSS 3.1
8.0 HIGH
EPSS
0.4% (33th percentile)
Weakness
CWE-269, CWE-284
NVD status
Analyzed
Published
2025-07-31
CVE-2025-52289 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2025-52289

Proof-of-concept code and exploit modules indexed by Sploitus