Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-52289 — Proof-of-concept for CVE-2025-52289: a broken access control vulnerability in MagnusBilling allowing unauthenticated privilege escalation from pending to active user status. | Kitploit
Tools/GitHubGitHub/madhav-bhardwaj/cve-2025-52289
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubmadhav-bhardwaj/cve-2025-52289

CVE-2025-52289

Proof-of-concept for CVE-2025-52289: a broken access control vulnerability in MagnusBilling allowing unauthenticated privilege escalation from pending to active user status.

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository
111 year agoNot yet reviewed

CVE-2025-52289: Broken Access Control in MagnusBilling < v7.8.5.3

Description

A Broken Access Control vulnerability exists in MagnusBilling versions prior to v7.8.5.3. Newly registered users can escalate their account status from pending to active without administrator approval by modifying a request parameter. This allows unauthorized access to system features intended only for verified users.

Impact

  • Severity: High
  • Vulnerability Type: Privilege Escalation / Broken Access Control
  • CVE ID: CVE-2025-52289

Patch

The issue was fixed in version v7.8.5.3.

  • 🔗 Vendor Patch Commit

Credits

Discovered by Madhav Bhardwaj

Download Tool