CNNVD-202512-3244 Information

CNNVD ID

CNNVD-202512-3244

CVE-2025-67174

  • CNNVD Published: 2025-12-17

Description (Chinese)

RiteCMS是一个网站CMS。 RiteCMS 3.1.0版本存在安全漏洞,该漏洞源于admin.php组件存在本地文件包含,可能导致通过目录遍历读取主机上的任意文件。

Description (English)

RiteCMS is a website CMS. There is a security loophole in version 3.1.0 of RiteCMS, which stems from the presence of local files contained in the admin.php component, which could lead to any file on the host being read through the directory.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

个人开发者

Published

2025-12-17

Last Modified

2026-02-24

References

https://github.com/handylulu/RiteCMS https://github.com/handylulu/RiteCMS/blob/master/admin.php#L46 https://github.com/handylulu/RiteCMS/blob/master/cms/subtemplates/settings.inc.tpl#L64 https://github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67174 https://access.redhat.com/security/cve/cve-2025-67174

Share on: