CVE-2025-52289
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
- Affected products
- Magnusbilling
- Magnussolution Magnusbilling
- = 7.8.5.3
- Fix
- Available
- CVSS 3.1
- 8.0 HIGH
- EPSS
- 0.4% (33th percentile)
- Weakness
- CWE-269, CWE-284
- NVD status
- Analyzed
- Published
- 2025-07-31
CVE-2025-52289 at NVD
1 known exploit for CVE-2025-52289
Proof-of-concept code and exploit modules indexed by Sploitus