Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-23282 | A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval. |
Wed, 06 Aug 2025 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:magnussolution:magnusbilling:7.8.5.3:*:*:*:*:*:*:* |
Mon, 04 Aug 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Magnussolution
Magnussolution magnusbilling |
|
| Vendors & Products |
Magnussolution
Magnussolution magnusbilling |
Thu, 31 Jul 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-269 CWE-284 |
|
| Metrics |
cvssV3_1
|
Thu, 31 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-07-31T15:48:06.390Z
Reserved: 2025-06-16T00:00:00.000Z
Link: CVE-2025-52289
Updated: 2025-07-31T15:46:55.517Z
Status : Analyzed
Published: 2025-07-31T15:15:37.263
Modified: 2025-08-06T16:37:10.657
Link: CVE-2025-52289
No data.
OpenCVE Enrichment
Updated: 2025-08-04T09:00:54Z
EUVD