CyberRota Analysis
AI-GeneratedThe Golo Framework versions up to and including 1.7.3 are vulnerable to a PHP Local File Inclusion (LFI) issue due to improper control of filenames in include/require statements. This vulnerability could allow an attacker to execute arbitrary PHP code on the server, potentially leading to unauthorized access and data compromise. Organizations using the Golo Framework should prioritize patching this vulnerability to mitigate risks associated with remote code execution.
Original NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in uxper Golo Framework golo-framework allows PHP Local File Inclusion.This issue affects Golo Framework: from n/a through <= 1.7.3.