CVE-2025-39429

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 98

Summary

CVE-2025-39429 is a filename manipulation vulnerability affecting the Széchenyi 2020 Logo software. This issue arises from the PHP application's improper control of included files. An attacker can exploit this vulnerability, known as PHP Remote File Inclusion, to gain unauthorized access to local files, potentially leading to significant security risks. The vulnerability exists in all versions of Széchenyi 2020 Logo, from none identified through 1.1. It is crucial for users to apply the necessary patches or upgrades to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share