Remote File Inclusion Vulnerability in Tribulant Software Newsletters
CVE-2025-54034
7.5HIGH
What is CVE-2025-54034?
A vulnerability exists in Tribulant Software Newsletters, allowing for PHP Local File Inclusion due to improper control of filenames in Include/Require statements. This can enable attackers to execute malicious scripts by including arbitrary local files in the application. The affected versions include Newsletters from 'n/a' through 4.10. It is crucial for users to review their current software versions and apply necessary updates to mitigate any risks.
Affected Version(s)
Newsletters <= 4.10