CVE-2023-30258
MagnusSolution MagnusBilling vulnerability analysis and mitigation

Overview

Command Injection vulnerability in MagnusSolution magnusbilling versions 6.x and 7.x allows remote attackers to execute arbitrary commands via unauthenticated HTTP requests. The vulnerability was discovered and reported on March 27, 2023, and was assigned CVE-2023-30258 on June 26, 2023. The affected software versions include MagnusBilling from version 6.0.0 up to and including version 7.3.0 (Advisory, NVD).

Technical details

The vulnerability exists in the lib/icepay/icepay.php file, specifically at line 753, where a demonstration code contains an unsafe exec() call. The vulnerability stems from insufficient sanitization of user-supplied inputs in the GET parameter 'democ', which is directly passed to the exec() function. The vulnerability has been assigned a CVSS v3.1 base score of 9.8 CRITICAL (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H) (NVD, Advisory).

Impact

An unauthenticated attacker can execute arbitrary OS commands with the privileges of the web server process (typically www-data or asterisk). At minimum, this allows attackers to compromise the billing system and its database. The vulnerability can be exploited remotely without any authentication requirements (Advisory, AttackerKB).

Mitigation and workarounds

The vulnerability has been patched by removing the demo code from icepay.php. Organizations should upgrade to the latest version of MagnusBilling that includes the fix, which was implemented in commit ccff9f6370f530cc41ef7de2e31d7590a0fdb8c3 (GitHub, Advisory).

Additional resources


SourceThis report was generated using AI

Related MagnusSolution MagnusBilling vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2023-30258CRITICAL9.8
  • MagnusSolution MagnusBillingMagnusSolution MagnusBilling
  • cpe:2.3:a:magnussolution:magnusbilling
NoNoJun 23, 2023
CVE-2025-52289HIGH8
  • MagnusSolution MagnusBillingMagnusSolution MagnusBilling
  • cpe:2.3:a:magnussolution:magnusbilling
NoNoJul 31, 2025
CVE-2025-2609MEDIUM6.1
  • MagnusSolution MagnusBillingMagnusSolution MagnusBilling
  • cpe:2.3:a:magnussolution:magnusbilling
NoNoMar 21, 2025
CVE-2025-2610MEDIUM5.4
  • MagnusSolution MagnusBillingMagnusSolution MagnusBilling
  • cpe:2.3:a:magnussolution:magnusbilling
NoNoMar 21, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management