Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2609

Опубликовано: 21 мар. 2025
Источник: nvd
CVSS3: 8.2
CVSS3: 6.1
EPSS Низкий

Описание

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:*
Версия до 7.3.0 (включая)

EPSS

Процентиль: 90%
0.05524
Низкий

8.2 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 8.2
github
11 месяцев назад

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users to store HTML content in the viewable log component accessible at /mbilling/index.php/logUsers/read" cross-site scripting This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

EPSS

Процентиль: 90%
0.05524
Низкий

8.2 High

CVSS3

6.1 Medium

CVSS3

Дефекты

CWE-79
CWE-79