|
|||
Rule General Information |
---|
Release Date: | 2025-05-28 | |
Rule Name: | MagnusBilling Alarm Moduls Cross-Site Scripting Vulnerability (CVE-2025-2610) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.This issue affects MagnusBilling: through 7.3.0. | |
Impact: | An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed. | |
Affected OS: | Windows, Linux, Others | |
Reference: | https://chocapikk.com/posts/2025/magnusbilling/ https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22 https://vulncheck.com/advisories/magnusbilling-alarm-xss https://chocapikk.com/posts/2025/magnusbilling/ |
|
Solutions |
---|
Please refer to announcements or patches release by the vendor: https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22 |