CVE-2025-27264

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 3, 2025
CWE ID 98

Summary

CVE-2025-27264 is a filename manipulation vulnerability affecting the NotFound Doctor Appointment Booking software. The issue stems from an improper control of include/require statements in PHP code, leading to a Local File Inclusion (LFI) vulnerability. An attacker can exploit this flaw to gain unauthorized access to the system by including and executing arbitrary PHP files on the affected server. This vulnerability exists in versions of Doctor Appointment Booking from n/a through 1.0.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share