CyberRota Analysis
AI-GeneratedThe vulnerability allows for improper control of filenames in PHP, leading to local file inclusion in the RT-Theme 18 and its extensions, specifically versions up to 2.5. This could enable an attacker to execute arbitrary PHP code, potentially compromising the server and exposing sensitive data. Organizations using affected versions of RT-Theme 18 should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows PHP Local File Inclusion.This issue affects RT-Theme 18 | Extensions: from n/a through <= 2.5.