CVE-2025-22973

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Feb 20, 2025
Updated: Feb 21, 2025
CWE ID 200

Summary

CVE-2025-22973 is a vulnerability affecting QiboSoft QiboCMS X1.0. This issue permits a remote attacker to access sensitive information through the http_curl() function, which is located in the '/application/common.php' file. The function directly retrieves URL response content, providing the attacker with unauthorized access to data. This vulnerability poses a significant risk to systems running QiboCMS X1.0 and requires immediate attention for patching or mitigation. Attackers can exploit this flaw to steal sensitive information and potentially gain unauthorized access to the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share