PHP Remote File Inclusion Vulnerability in FULL Customer by FULL SERVICES
CVE-2025-26757

7.5HIGH

Key Information:

Vendor
Full Services
Status
Full Customer
Vendor
CVE Published:
22 February 2025

Summary

A PHP Remote File Inclusion vulnerability has been identified in the FULL Customer product by FULL SERVICES, allowing attackers to exploit improper control of filename handling in include or require statements. This flaw can lead to local file inclusion, potentially allowing unauthorized access to sensitive files on the server. Affected versions range from n/a through 3.1.26, making it crucial for users to implement necessary security patches to mitigate risks associated with this vulnerability.

Affected Version(s)

FULL Customer <= 3.1.26

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dimas Maulana (Patchstack Alliance)
.