CVE-2025-39379

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 98

Summary

CVE-2025-39379 is a newly disclosed vulnerability affecting Capturly, an unspecified version of which allows for PHP Local File Inclusion. This issue arises due to the application's improper handling of include/require statements and their filenames. An attacker can exploit this vulnerability to access and execute arbitrary local files, posing a significant risk to the affected system's security and integrity. Capturly versions from n/a to 2.0.1 are reportedly affected by this PHP Remote File Inclusion (RFI) vulnerability. System administrators are urged to update to the latest, patched version as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share