HIGH
A Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted request to /mbilling/index.php/user/save to set their account status fom "pending" to "active" without requiring administrator approval
Published Jul 31, 2025
8.0
HIGHCVSS 3.1
EPSS 0.41%
Description
Affected products
Remediation
References (2)
Change history (0)
No recorded changes yet.