CVE-2025-32150

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 4, 2025
Updated: Apr 7, 2025
CWE ID 98

Summary

CVE-2025-32150 is a filename manipulation vulnerability affecting the Rameez Iqbal Real Estate Manager software. This issue, classified as a PHP Local File Inclusion (LFI) vulnerability, enables an attacker to gain unauthorized access to local files by exploiting improper control of include/require statements in PHP programs. The vulnerability can be exploited remotely and impacts versions of the software from n/a through 7.3. An attacker could potentially use this flaw to access sensitive information or execute malicious code on the affected system.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share