CVE-2025-27015

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 26, 2025
Updated: Mar 27, 2025
CWE ID 98

Summary

CVE-2025-27015 is a new vulnerability affecting the Hostiko platform before version 30.1. This issue involves an improper control of filename for include/require statements in PHP programs, leading to a Local File Inclusion (LFI) vulnerability. Attackers can exploit this flaw to access and run arbitrary local files, potentially leading to data theft or system compromise. The PHP Remote File Inclusion (RFI) technique could also be employed if the web server's configuration allows it, posing a more severe threat. Hostiko users are urged to update their platforms as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share