CVE-2025-39526
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-39526 is a filename manipulation vulnerability affecting the nicdark Hotel Booking system. This issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, enables an attacker to include local files by manipulating the include/require statement in PHP programs used by the system. The flaw, which impacts versions of the Hotel Booking software from undisclosed to 3.6, could potentially allow an attacker to access sensitive information or execute arbitrary code. Unauthorized access or control of the affected system could lead to serious consequences, including data theft or system compromise. It is highly recommended that users of the nicdark Hotel Booking system upgrade to a patched version as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.