RULE(RULE ID:338979)

Rule General Information
Release Date: 2025-05-28
Rule Name: MagnusBilling Alarm Moduls Cross-Site Scripting Vulnerability (CVE-2025-2610)
Severity:
CVE ID:
Rule Protection Details
Description: Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.This issue affects MagnusBilling: through 7.3.0.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://chocapikk.com/posts/2025/magnusbilling/
https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22
https://vulncheck.com/advisories/magnusbilling-alarm-xss
https://chocapikk.com/posts/2025/magnusbilling/
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22