PT-2025-52746 · Unknown · Thembay Diza

João Pedro S Alcântara

+1

·

Published

2025-12-23

·

Updated

2025-12-28

·

CVE-2025-68544

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Thembay Diza versions through 1.3.15
Description An improper control of filename for include/require statement exists in Thembay Diza, leading to a PHP Local File Inclusion issue. This allows for the inclusion of local files, potentially leading to code execution or information disclosure. The vulnerability stems from insufficient validation of file paths used in include or require statements within the application.
Recommendations Update Thembay Diza to a version later than 1.3.15.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-68544

Affected Products

Thembay Diza