CVE-2025-23945
CVSS 3.1 Score 7.5 of 10 (high)
Details
Summary
CVE-2025-23945 is a new vulnerability affecting Popliup, a PHP application. The issue involves improper control of filenames used in include or require statements, leading to a Local File Inclusion (LFI) vulnerability. This weakness allows an attacker to include and access arbitrary local files on the affected system. The vulnerability has been identified in all versions of Popliup from n/a through 1.1.1. Successful exploitation could grant unauthorized access or disclosure of sensitive information. Users are advised to update their Popliup installations to the latest version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.