CVE-2025-32141
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 98
Summary
CVE-2025-32141 is a filename manipulation vulnerability affecting the Stylemix MasterStudy Learning Management System. The issue permits PHP Local File Inclusion, enabling an attacker to include and execute arbitrary PHP files on affected systems. This vulnerability exists due to improper control of filenames used in include/require statements. The impacted versions of MasterStudy LMS range from n/a to 3.5.23. It is crucial for users to apply patches or updates to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.