# CVE-2025-52289: Broken Access Control in MagnusBilling < v7.8.5.3
## Description
A **Broken Access Control** vulnerability exists in **MagnusBilling** versions prior to `v7.8.5.3`. Newly registered users can escalate their account status from `pending` to `active` without administrator approval by modifying a request parameter. This allows unauthorized access to system features intended only for verified users.
## Impact
- **Severity:** High
- **Vulnerability Type:** Privilege Escalation / Broken Access Control
- **CVE ID:** CVE-2025-52289
## Patch
The issue was fixed in version `v7.8.5.3`.
- 🔗 [Vendor Patch Commit](https://github.com/magnussolution/magnusbilling7/commit/f886330e9e9216a3830775610a4a83f970c08e8d)
## Credits
Discovered by **Madhav Bhardwaj**
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view