CVE-2025-23915

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 16, 2025
CWE ID 98

Summary

CVE-2025-23915 is a filename manipulation vulnerability affecting Roninwp FAT Event Lite, from an undisclosed version up to 1.1. An attacker can exploit this PHP Remote File Inclusion (RFI) issue to include local files on the vulnerable server, potentially leading to information disclosure or code execution. The vulnerability occurs due to the software's lack of proper control over filenames in include/require statements.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share