CVE-2025-39526

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Apr 17, 2025
CWE ID 98

Summary

CVE-2025-39526 is a filename manipulation vulnerability affecting the nicdark Hotel Booking system. This issue, classified as a PHP Remote File Inclusion (RFI) vulnerability, enables an attacker to include local files by manipulating the include/require statement in PHP programs used by the system. The flaw, which impacts versions of the Hotel Booking software from undisclosed to 3.6, could potentially allow an attacker to access sensitive information or execute arbitrary code. Unauthorized access or control of the affected system could lead to serious consequences, including data theft or system compromise. It is highly recommended that users of the nicdark Hotel Booking system upgrade to a patched version as soon as possible to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share