PT-2025-52746 · Unknown · Thembay Diza

·

CVE-2025-68544

·

Published

2025-12-23

·

Updated

2025-12-28

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thembay Diza versions through 1.3.15
Description An improper control of filename for include/require statement exists in Thembay Diza, leading to a PHP Local File Inclusion issue. This allows for the inclusion of local files, potentially leading to code execution or information disclosure. The vulnerability stems from insufficient validation of file paths used in include or require statements within the application.
Recommendations Update Thembay Diza to a version later than 1.3.15.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-68544

Affected Products

Thembay Diza