CVE-2025-39399
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 98
Summary
CVE-2025-39399 is a filename control vulnerability affecting the Ashraful Sarkar Naiem License For Envato software. This issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, enables an attacker to include and potentially execute arbitrary local PHP files by manipulating the filename in an include/require statement. The vulnerability impacts versions of the software from n/a to 1.0.0, placing affected users at risk of code injection and unauthorized access.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.