Sploitus

Exploit for Improper Privilege Management in Magnussolution Magnusbilling

githubexploit Β· 2025-07-31

Exploit Code

README22 lines
## https://sploitus.com/exploit?id=A833F8FF-B4EC-50A5-B213-55060270C1FD
# CVE-2025-52289: Broken Access Control in MagnusBilling < v7.8.5.3

## Description

A **Broken Access Control** vulnerability exists in **MagnusBilling** versions prior to `v7.8.5.3`. Newly registered users can escalate their account status from `pending` to `active` without administrator approval by modifying a request parameter. This allows unauthorized access to system features intended only for verified users.

## Impact

- **Severity:** High  
- **Vulnerability Type:** Privilege Escalation / Broken Access Control  
- **CVE ID:** CVE-2025-52289

## Patch

The issue was fixed in version `v7.8.5.3`.

- πŸ”— [Vendor Patch Commit](https://github.com/magnussolution/magnusbilling7/commit/f886330e9e9216a3830775610a4a83f970c08e8d)

## Credits

Discovered by **Madhav Bhardwaj**