S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated May 23, 2025

CVE-2025-2610 Scanner

CVE-2025-2610 Scanner - Cross-Site Scripting vulnerability in MagnusBilling

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
3.1k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2025-2610
7.6
CVSShigh
Exploitable remotely over the internet · low-privilege account sufficient · user interaction needed.

Improper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated stored cross-site scripting. This vulnerability is associated with program files protected/components/MagnusLog.Php. This issue affects MagnusBilling: through 7.3.0.

Attack Vector
Network
Privileges Req.
Low
User Interaction
Required
Affected
MagnusBillingby MagnusSolution
0
Updated Sep 9, 2026View on NVD →
Detail

MagnusBilling is a telecommunications platform used by businesses to manage billing and related tasks. The software is designed to integrate various communication protocols and billing solutions under a single platform. MagnusBilling's system is popular among VoIP providers and telecom operators due to its comprehensive features. It supports modules like the Alarm Module, enabling greater flexibility and control for businesses. The platform is particularly valued for its customization capabilities, allowing easy adaptation to specific business needs. Its user-friendly interface is built to simplify the billing process while maintaining accuracy and efficiency.

Cross-Site Scripting (XSS) is a commonly known vulnerability where attackers inject malicious scripts into webpages viewed by other users. This vulnerability can have serious implications, including data theft and account takeover. In the context of MagnusBilling, the vulnerability could be exploited by injecting scripts that execute malicious actions within the user's session. XSS vulnerabilities are particularly potent because they allow attackers to execute scripts within the context of a user's browser session. However, for successful exploitation, attackers often need users to perform specific actions, such as clicking a link. Organizations must identify and mitigate XSS vulnerabilities quickly to prevent abuse.

The vulnerability resides in MagnusBilling's Alarm Module, specifically within the MagnusLog.Php file. Attackers can exploit this by crafting a specific request to the MagnusBilling application. The affected endpoint includes "/mbilling/index.php/alarm/save", where input is improperly sanitized. To exploit this, an attacker injects a script in the 'message' field that is executed as soon as a user views the alarm logs. Successful attacks can execute scripts in users' browsers, leading to potential data exposure and unauthorized actions. However, the attacker needs prior authentication to inject the malicious code effectively.

If this vulnerability is exploited, it could lead to unauthorized actions being performed within the MagnusBilling system. Users may experience unauthorized transactions due to script execution. Sensitive data can be exfiltrated, such as user credentials and financial information. Moreover, the system's integrity could be compromised, affecting its reliability and user trust. Victims might also experience session hijacking, where attackers gain control over their accounts during active sessions. Long-term consequences could include financial losses and reputational damage for affected organizations.

REFERENCES

Solution Advice
  • Ensure proper input validation is in place to neutralize untrusted data before use.
  • Implement Content Security Policy (CSP) headers to restrict resources a webpage can load.
  • Regularly update and patch MagnusBilling to the latest version to incorporate security fixes.
  • Conduct regular security assessments and code reviews to identify areas of risk.
  • Provide user education on avoiding risky behaviors that can lead to XSS exploitation.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2025-2610 Scanner - Cross-Site Scripting vulnerability in MagnusBilling | S4E