PT-2025-27094 · Unknown · Serped.Net

Timomangcut

·

Published

2025-06-27

·

Updated

2025-06-27

·

CVE-2025-28998

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SERPed.net versions n/a through 4.6
Description: The issue is related to an Improper Control of Filename for Include/Require Statement in PHP Program, also known as 'PHP Remote File Inclusion', which allows PHP Local File Inclusion. This is a type of security vulnerability that can be exploited by manipulating the filename parameter in include or require statements in PHP programs, potentially leading to the execution of arbitrary code or the disclosure of sensitive information.
Recommendations: For SERPed.net versions n/a through 4.6, consider restricting access to the include or require statements to minimize the risk of exploitation until a patch is available. As a temporary workaround, review and validate all filenames used in include or require statements to prevent potential manipulation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2025-28998

Affected Products

Serped.Net