PHP Local File Inclusion Vulnerability in Ach Invoice App by Service Shogun
CVE-2025-22364
7.5HIGH
What is CVE-2025-22364?
The Ach Invoice App by Service Shogun is susceptible to a PHP Local File Inclusion vulnerability due to improper handling of filename inputs during include or require statements. This vulnerability could allow attackers to include files from the local server, potentially exposing sensitive data and enabling further compromises. Versions up to 1.0.1 are affected, which highlights the urgent need for users to update their applications to mitigate this risk.
Affected Version(s)
Ach Invoice App <= 1.0.1