CVE-2025-26889

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 15, 2025
CWE ID 98

Summary

CVE-2025-26889 is a filename vulnerability affecting NotFound hockeydata LOS, where improper control of include/require statements in PHP programs allows an attacker to perform local file inclusion. This issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, can potentially be exploited to access or modify sensitive files on affected systems. The vulnerability exists in versions of hockeydata LOS from n/a through 1.2.4. System administrators are advised to apply the necessary patches or upgrades to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share