CVE-2025-22656

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Feb 18, 2025
CWE ID 98

Summary

CVE-2025-22656 is a newly identified vulnerability affecting the Oscar Alvarez Cookie Monster software, specifically versions from n/a to 1.2.2. This issue is classified as a Local File Inclusion (LFI) vulnerability, where an attacker can manipulate the filename in an include or require statement to access local files. In this case, an improper control of the filename led to the PHP Remote File Inclusion vulnerability, making it possible for an attacker to include and execute arbitrary PHP code on the affected system. Such unauthorized access could lead to information disclosure, system compromise, or further exploitation. It is essential for users to apply the necessary patches or upgrades to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share