PT-2026-4015 · Bzotheme · Mella

Published

2026-01-22

·

Updated

2026-01-22

·

CVE-2025-67616

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mella versions prior to 1.2.30
Description Improper control of the filename for the Include/Require statement in the PHP program allows for Local File Inclusion. This occurs when the application does not sufficiently validate the file paths used in include or require functions, potentially allowing an attacker to read or execute files on the server.
Recommendations Update to a version later than 1.2.29.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-67616

Affected Products

Mella