Local File Inclusion Vulnerability in Axiomthemes Confidant Product
CVE-2025-53440
8.1HIGH
What is CVE-2025-53440?
A local file inclusion vulnerability exists in the Axiomthemes Confidant product, allowing unauthorized access to files on the web server. This flaw arises from improper control of filenames in PHP include/require statements, potentially enabling attackers to load and execute arbitrary PHP files. This issue impacts users running any version of Confidant up to 1.4, posing a significant risk for data exposure and server compromise.
Affected Version(s)
Confidant <= 1.4