CVE-2025-39429
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Apr 17, 2025
CWE ID 98
Summary
CVE-2025-39429 is a filename manipulation vulnerability affecting the Széchenyi 2020 Logo software. This issue arises from the PHP application's improper control of included files. An attacker can exploit this vulnerability, known as PHP Remote File Inclusion, to gain unauthorized access to local files, potentially leading to significant security risks. The vulnerability exists in all versions of Széchenyi 2020 Logo, from none identified through 1.1. It is crucial for users to apply the necessary patches or upgrades to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- WordPress