VendorsMagnusSolutionmagnusbilling7.8.5.3
Vulnerabilities

MagnusSolution MagnusBilling 7.8.5.3

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

1CVEs
CVE-2025-52289
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
Published 2025-07-31 · Analyzed
8.0EPSS 0.004