CVE-2025-31082

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Apr 1, 2025
Updated: Apr 2, 2025
CWE ID 98

Summary

CVE-2025-31082 is a filename manipulation vulnerability affecting the InfornWeb News & Blog Designer Pack, which can lead to PHP Local File Inclusion. The issue arises due to improper control of include/require statements in the software. This vulnerability allows an attacker to potentially gain unauthorized access to local files, posing a significant risk to data confidentiality and integrity. The affected versions of News & Blog Designer Pack include those from the unspecified version n/a up to 4.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share