CVE-2025-39359
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 98
Summary
CVE-2025-39359 is a vulnerability affecting the Code Work Web (CWW) Portfolio software. It involves an improper filename control for include/require statements in PHP programs, leading to a PHP Local File Inclusion issue. This vulnerability allows an attacker to access and read local files on the affected system, posing a serious security risk. The vulnerability is found in CWW Portfolio versions from n/a through 1.3.1. System administrators are advised to update to the latest version to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.