CVE-2025-52289: Magnussolution Magnusbilling
High severity, CVSS 8.0. EPSS: 0.4% chance of exploitation in the next 30 days.
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval.
Affected products
- Magnussolution Magnusbilling: version 7.8.5.3 only
Published 2025-07-31. Last modified 2026-06-17.