PHP Remote File Inclusion Vulnerability in FULL Customer by FULL SERVICES
CVE-2025-26757
7.5HIGH
What is CVE-2025-26757?
A PHP Remote File Inclusion vulnerability has been identified in the FULL Customer product by FULL SERVICES, allowing attackers to exploit improper control of filename handling in include or require statements. This flaw can lead to local file inclusion, potentially allowing unauthorized access to sensitive files on the server. Affected versions range from n/a through 3.1.26, making it crucial for users to implement necessary security patches to mitigate risks associated with this vulnerability.
Affected Version(s)
FULL Customer <= 3.1.26