PHP Local File Inclusion in Redbasic Theme for Hubzilla
CVE-2022-27256

6.1MEDIUM

Key Information:

Vendor

Hubzilla

Status
Vendor
CVE Published:
13 April 2022

What is CVE-2022-27256?

A local file inclusion vulnerability exists in the Redbasic theme for Hubzilla prior to version 7.2. This flaw enables remote attackers to exploit the 'schema' parameter, allowing them to include arbitrary PHP files. Successful exploitation could lead to unauthorized access to sensitive information and further compromise the application’s integrity. Users and administrators of Hubzilla are encouraged to update to the latest version to mitigate the risks associated with this vulnerability.

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.