PHP Remote File Inclusion Vulnerability in CMSMasters Content Composer by Cmsmasters
CVE-2025-4414
8.1HIGH
What is CVE-2025-4414?
The CMSMasters Content Composer is vulnerable to an improper control of filenames during include or require statements in PHP. This vulnerability allows for PHP Local File Inclusion, potentially leading to exposure of sensitive files on the server. Attackers could exploit this issue to manipulate file inclusions, resulting in unauthorized access to system files or executing arbitrary code. It is crucial for users and site administrators to prioritize updates and implement security measures to mitigate this vulnerability.
Affected Version(s)
CMSMasters Content Composer < 2.5.7