PHP Remote File Inclusion Vulnerability in FULL Customer by FULL SERVICES
CVE-2025-26757
7.5HIGH
Key Information:
- Vendor
- Full Services
- Status
- Full Customer
- Vendor
- CVE Published:
- 22 February 2025
Summary
A PHP Remote File Inclusion vulnerability has been identified in the FULL Customer product by FULL SERVICES, allowing attackers to exploit improper control of filename handling in include or require statements. This flaw can lead to local file inclusion, potentially allowing unauthorized access to sensitive files on the server. Affected versions range from n/a through 3.1.26, making it crucial for users to implement necessary security patches to mitigate risks associated with this vulnerability.
Affected Version(s)
FULL Customer <= 3.1.26
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dimas Maulana (Patchstack Alliance)