PHP Local File Inclusion Vulnerability in Ach Invoice App by Service Shogun
CVE-2025-22364
7.5HIGH
Summary
The Ach Invoice App by Service Shogun is susceptible to a PHP Local File Inclusion vulnerability due to improper handling of filename inputs during include or require statements. This vulnerability could allow attackers to include files from the local server, potentially exposing sensitive data and enabling further compromises. Versions up to 1.0.1 are affected, which highlights the urgent need for users to update their applications to mitigate this risk.
Affected Version(s)
Ach Invoice App <= 1.0.1
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
tahu.datar (Patchstack Alliance)