PHP Remote File Inclusion Vulnerability in JobSearch by eyecix
CVE-2025-52806
7.5HIGH
What is CVE-2025-52806?
The JobSearch plugin by eyecix contains a vulnerability due to improper control of filename handling in its PHP include/require statements. This allows attackers to potentially exploit local file inclusion, enabling unauthorized access to sensitive files on the server. Affected versions range from an unspecified release to 2.9.0. It is crucial for users of this plugin to implement necessary updates and security measures to protect against this risk.
Affected Version(s)
JobSearch <= 2.9.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)