{"id":"CVE-2025-2609","title":"Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…","summary":"Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/lo…","severity":"high","cvss":8.2,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N","cwe":["CWE-79","CWE-79"],"vendor":"magnussolution","product":"magnusbilling","affected":["magnusbilling <= 7.3.0"],"published":"2025-03-21","updated":"2026-07-14","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-2609","references":[{"url":"https://chocapikk.com/posts/2025/magnusbilling/","label":"disclosure@vulncheck.com"},{"url":"https://github.com/magnussolution/magnusbilling7/commit/f0f083c76157e31149ae58342342fb1bf1629e22","label":"disclosure@vulncheck.com"},{"url":"https://vulncheck.com/advisories/magnusbilling-logs-xss","label":"disclosure@vulncheck.com"},{"url":"https://chocapikk.com/posts/2025/magnusbilling/","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd","exploit-available"],"epss":0.01129,"epssPercentile":0.64955,"ingestedAt":"2026-07-15T12:43:54.204Z","exploits":{"nuclei":["CVE-2025-2609"],"checkedAt":"2026-09-23T07:13:35.248Z"},"exploitAvailable":true,"slug":"CVE-2025-2609","body":"## Overview\n\nImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read\" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.\n\nThis issue affects MagnusBilling: through 7.3.0.\n\n## Affected\n\n- `magnusbilling <= 7.3.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":57,"depthScoreParts":{"impact":45.1,"likelihood":0.2,"exploitation":12,"ransomware":0},"changes":[{"seq":4800,"id":"CVE-2025-2609","ts":1788887207769,"field":"exploit_available","old":"false","new":"true"},{"seq":3683,"id":"CVE-2025-2609","ts":1788886324384,"field":"exploit_available","old":"true","new":"false"},{"seq":2530,"id":"CVE-2025-2609","ts":1788883003885,"field":"exploit_available","old":"false","new":"true"},{"seq":1559,"id":"CVE-2025-2609","ts":1788882405564,"field":"exploit_available","old":"true","new":"false"},{"seq":673,"id":"CVE-2025-2609","ts":1788881843348,"field":"exploit_available","old":"false","new":"true"}]}