PHP Remote File Inclusion Vulnerability in MojoJoomla School Management
CVE-2025-47572

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
17 June 2025

What is CVE-2025-47572?

The MojJoomla School Management software is affected by a vulnerability that permits PHP Local File Inclusion due to improper control over the filename in the include or require statements. This flaw can potentially allow attackers to execute malicious code on the server, leading to unauthorized access to the system. Affected versions of the product extend from none up to 93.0.0, posing risks to users who may not have updated to the latest secure releases.

Affected Version(s)

School Management <= 93.0.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ann (Patchstack Alliance)
.
CVE-2025-47572 : PHP Remote File Inclusion Vulnerability in MojoJoomla School Management