PT-2025-33173 · Unknown · Geo Mashup

Dimas Maulana

·

Published

2025-08-14

·

Updated

2025-08-14

·

CVE-2025-48293

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Geo Mashup versions through 1.13.16
Description: A flaw exists in the handling of filename control for include/require statements within a PHP program, specifically a PHP Local File Inclusion issue in Dylan Kuhn Geo Mashup. This allows for the local inclusion of files in PHP.
Recommendations: Update Geo Mashup to a version later than 1.13.16.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-48293

Affected Products

Geo Mashup