CVE-2025-30901

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Apr 1, 2025
CWE ID 98

Summary

CVE-2025-30901 is a new vulnerability affecting the JoomSky JS Help Desk software. This issue involves an improper control of filename for include/require statements in PHP code, resulting in a Local File Inclusion (LFI) vulnerability. Attackers can exploit this weakness to gain unauthorized access to sensitive files on affected systems. The vulnerability exists in versions of JS Help Desk from n/a through 2.9.2, making a significant number of installations potentially at risk. It is essential for users to update to a patched version as soon as possible to mitigate the threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share