Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-2610

Опубликовано: 21 мар. 2025
Источник: nvd
CVSS3: 7.6
CVSS3: 5.4
EPSS Низкий

Описание

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php.

This issue affects MagnusBilling: through 7.3.0.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:magnussolution:magnusbilling:*:*:*:*:*:*:*:*
Версия до 7.3.0 (включая)

EPSS

Процентиль: 84%
0.02286
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79

Связанные уязвимости

CVSS3: 7.6
github
11 месяцев назад

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

EPSS

Процентиль: 84%
0.02286
Низкий

7.6 High

CVSS3

5.4 Medium

CVSS3

Дефекты

CWE-79
CWE-79