CyberRota Analysis
AI-GeneratedThe vulnerability in ThemeMove Brook allows for local file inclusion due to improper control of filenames in PHP include/require statements, potentially enabling an attacker to execute arbitrary PHP code on the server. This poses a significant risk to any installations of Brook version 2.9.0 or earlier, as it can lead to unauthorized access and manipulation of sensitive files. Organizations using this software should prioritize patching or upgrading to mitigate the risk associated with this high-severity vulnerability.
Original NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Brook brook allows PHP Local File Inclusion.This issue affects Brook: from n/a through <= 2.9.0.