Vulnerability Description
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Magnussolution | Magnusbilling | 7.8.5.3 |
Related Weaknesses (CWE)
References
- https://github.com/Madhav-Bhardwaj/CVE-2025-52289Third Party Advisory
- https://github.com/magnussolution/magnusbilling7/commit/f886330e9e9216a383077561Patch
FAQ
What is CVE-2025-52289?
CVE-2025-52289 is a vulnerability with a CVSS score of 8.0 (HIGH). A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their ac...
How severe is CVE-2025-52289?
CVE-2025-52289 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-52289?
Check the references section above for vendor advisories and patch information. Affected products include: Magnussolution Magnusbilling.