CVE-2025-31432

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 28, 2025
CWE ID 98

Summary

CVE-2025-31432 is a filename manipulation vulnerability affecting the Chop Chop Pop-Up Chop Shop software. The PHP Remote File Inclusion (RFI) vulnerability enables an attacker to include and execute arbitrary local files, posing a significant security risk. The flaw occurs due to improper control of the filename for include/require statements in the PHP program. This issue impacts Chop Chop Pop-Up Chop Shop versions 2.1.7 and below. Attackers can leverage this vulnerability to gain access to sensitive data or even execute malicious code, potentially resulting in data breaches and unauthorized system access.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share