
Proof-of-concept for CVE-2025-52289: a broken access control vulnerability in MagnusBilling allowing unauthenticated privilege escalation from pending to active user status.
A Broken Access Control vulnerability exists in MagnusBilling versions prior to v7.8.5.3. Newly registered users can escalate their account status from pending to active without administrator approval by modifying a request parameter. This allows unauthorized access to system features intended only for verified users.
The issue was fixed in version v7.8.5.3.
Discovered by Madhav Bhardwaj