HTTP RULE(RULE ID:338980)

Rule General Information
Release Date: 2025-05-28
Rule Name: MagnusBilling Cross Site Scripting Vulnerability (CVE-2025-2609)
Severity: High
CVE ID: CVE-2025-2609
Rule Protection Details
Description: Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.This issue affects MagnusBilling: through 7.3.0.
Impact: An attacker can conduct a cross-site scripting attack to inject malicious client-side scripts into web pages viewed by other users, or to bypass access controls such as the same-origin policy, if affected version is installed.
Affected OS: Windows, Linux, Others
Reference: https://chocapikk.com/posts/2025/magnusbilling/
https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22
https://vulncheck.com/advisories/magnusbilling-logs-xss
https://chocapikk.com/posts/2025/magnusbilling/
Solutions
Please refer to announcements or patches release by the vendor: https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22