CVE-2025-26137
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Mar 18, 2025
Updated: Apr 1, 2025
CWE ID 98
Summary
CVE-2025-26137 is a newly identified vulnerability affecting Systemic Risk Value version 2.8.0 and below. This issue permits an unauthenticated attacker to execute Local File Inclusion attacks through the GetFile.aspx endpoint. By supplying a crafted file path, the attacker can read arbitrary system files, potentially exposing sensitive information. System administrators are urged to upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.