PT-2025-52746 · Unknown · Thembay Diza
João Pedro S Alcântara
+1
·
Published
2025-12-23
·
Updated
2025-12-28
·
CVE-2025-68544
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Thembay Diza versions through 1.3.15
Description
An improper control of filename for include/require statement exists in Thembay Diza, leading to a PHP Local File Inclusion issue. This allows for the inclusion of local files, potentially leading to code execution or information disclosure. The vulnerability stems from insufficient validation of file paths used in include or require statements within the application.
Recommendations
Update Thembay Diza to a version later than 1.3.15.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Thembay Diza