PT-2025-6956 · Unknown · Oscar Alvarez Cookie Monster

Lvt-Tholv2K

·

Published

2025-02-18

·

Updated

2025-02-18

·

CVE-2025-22656

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Oscar Alvarez Cookie Monster versions 1.2.2 and earlier
Description: The issue is related to improper control of filename for include/require statement in PHP program, allowing PHP Local File Inclusion. This is also known as 'PHP Remote File Inclusion'.
Recommendations: For versions 1.2.2 and earlier, consider disabling the include/require statement functionality until a patch is available. Restrict access to sensitive files and directories to minimize the risk of exploitation. Avoid using user-supplied input for filenames in include/require statements.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-22656

Affected Products

Oscar Alvarez Cookie Monster