PT-2026-27974 · Mikado Themes · Belfort

Publicado

2026-03-25

·

Atualizado

2026-03-29

·

CVE-2026-27075

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mikado-Themes Belfort versions n/a through 1.0
Description A flaw exists in the handling of filenames used in include/require statements within a PHP program, specifically a PHP Local File Inclusion issue in Mikado-Themes Belfort. This allows for the inclusion of local PHP files. The Include/Require statement does not properly validate the filename, leading to the possibility of including arbitrary files.
Recommendations Versions prior to 1.0 should be updated.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27075

Produtos afetados

Belfort