CVE-2025-30901
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-30901 is a new vulnerability affecting the JoomSky JS Help Desk software. This issue involves an improper control of filename for include/require statements in PHP code, resulting in a Local File Inclusion (LFI) vulnerability. Attackers can exploit this weakness to gain unauthorized access to sensitive files on affected systems. The vulnerability exists in versions of JS Help Desk from n/a through 2.9.2, making a significant number of installations potentially at risk. It is essential for users to update to a patched version as soon as possible to mitigate the threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.