THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-2609 (HIGH 8.2) — Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vuln

[NVD] CVE-2025-2609 (HIGH 8.2) — Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vuln

lownvdPublished 2025-03-21

CVE-2025-2609 CVSS: 8.2 HIGH Published: 2025-03-21T23:15:21.493

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/co

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2609