THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-2610 (HIGH 7.6) — Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue a

[NVD] CVE-2025-2610 (HIGH 7.6) — Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue a

lownvdPublished 2025-03-21

CVE-2025-2610 CVSS: 7.6 HIGH Published: 2025-03-21T23:15:21.613

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-2610