← Vulnerability feed

Vulnerability record · CVE-2023-30258 · published 23 June 2023

CVE-2023-30258: MagnusBilling OS Command Injection via Unauthenticated HTTP Request

Magnussolution · Magnusbilling

MagnusBilling 6.x and 7.x contain an OS command injection flaw (CWE-78/CWE-77) that lets remote attackers execute arbitrary commands through an unauthenticated HTTP request. The vulnerability is trivially reachable over the network with no credentials or user interaction, making it a severe risk for any exposed instance.

9.8 CVSS 3.1 Critical EPSS 94% · top 0.2% CWE-78 · OS command injectionCWE-77 · Command injection
9.8CVSS 3.1 base score
94%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
7References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

Command Injection vulnerability in MagnusSolution magnusbilling 6.x and 7.x allows remote attackers to run arbitrary commands via unauthenticated HTTP request.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.8 with no authentication or user interaction required, combined with a very high EPSS score and public exploit code, makes this an urgent remote code execution risk.

What it is

MagnusBilling 6.x and 7.x contain an OS command injection flaw (CWE-78/CWE-77) that lets remote attackers execute arbitrary commands through an unauthenticated HTTP request. The vulnerability is trivially reachable over the network with no credentials or user interaction, making it a severe risk for any exposed instance.

Impact

An attacker can run arbitrary operating system commands on the server, leading to full compromise of the application and potentially the underlying host. This can result in data theft, service disruption, or use of the server as a pivot point.

Attack surface

The flaw is reached over the network via HTTP requests to the MagnusBilling web interface. No authentication or user interaction is required, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

Public exploit code and a third-party advisory are referenced, and EPSS indicates a very high probability of exploitation (0.9425, 99.845th percentile). The CVE is not listed in CISA KEV, so no confirmed in-the-wild exploitation is documented in this record.

What to do

  • Apply the vendor patch referenced in the MagnusBilling7 commit ccff9f6370f530cc41ef7de2e31d7590a0fdb8c3 as soon as possible.
  • Restrict network access to the MagnusBilling web interface using firewalls or VPNs so it is not exposed to untrusted networks.
  • Review and harden any input handling that passes user-supplied data to system commands; avoid shell execution where possible.
  • Monitor for and block exploitation attempts using the public proof-of-concept and advisory details.
  • If patching is delayed, consider temporarily disabling or isolating the affected service.

Detection

  • Inspect HTTP request logs for suspicious parameters or patterns that may indicate command injection attempts against MagnusBilling endpoints.
  • Monitor server process creation for unexpected child processes spawned by the web server (e.g., shell commands, curl, wget).
  • Use file integrity monitoring on web-accessible directories and system binaries to detect post-exploitation changes.
  • Deploy network signatures or WAF rules targeting known exploit patterns from the public advisory and PoC.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-30258 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.0CVE-2025-52289Magnussolution magnusbilling improper privilege management vulnerabilityA Broken Access Control vulnerability in MagnusBilling v7.8.5.3 allows newly registered users to gain escalated privileges by sending a crafted reque…EPSS 0.42%6.1CVE-2025-2609Magnussolution magnusbilling cross-site scripting vulnerabilityImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling login logging allows unauthenticated users …EPSS 1.1%5.4CVE-2025-2610Magnussolution magnusbilling cross-site scripting vulnerabilityImproper neutralization of input during web page generation vulnerability in MagnusSolution MagnusBilling (Alarm Module modules) allows authenticated…EPSS 0.94%8.8CVE-2026-53266Linux kernel ebtables SNAT out-of-bounds write in ARP rewriteThe ebtables SNAT target rewrites the ARP sender hardware address via skb_store_bits() without first making that range writable. When the ARP SHA byt…KEVEPSS 0.65%analysed8.8CVE-2026-87491Google Chrome V8 out-of-bounds write enables sandbox code executionChrome before 153.0.8010.36 contains an out-of-bounds write in the V8 JavaScript engine. A crafted HTML page can trigger the memory corruption, and b…KEVEPSS 3.1%analysed9.8CVE-2025-25249Fortinet FortiOS and FortiSwitchManager heap buffer overflow via crafted packetsA heap-based buffer overflow (CWE-122/CWE-787) in Fortinet FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 through 7.2.6 lets an unauthenticated…KEVEPSS 3.9%analysed7.8CVE-2026-83549SonicWall SMA1000 AMC OS Command InjectionThe SMA1000 Appliance Management Console contains an OS command injection flaw (CWE-78) that lets an authenticated administrator execute arbitrary op…KEVEPSS 11%analysed10.0CVE-2026-49869Kestra OSS auth bypass via path suffix match enables RCEKestra OSS AuthenticationFilter whitelists the public config endpoint using request.getPath().endsWith("/configs"), a suffix match instead of an exac…KEVEPSS 2.1%analysed

Source: NIST National Vulnerability Database (record CVE-2023-30258), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.