CVE-2022-27256

MEDIUM

hubzilla < 7.2 - Local File Inclusion via Redbasic Theme Schema Parameter

Title source: llm
STIX 2.1

Description

A PHP Local File inclusion vulnerability in the Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.

References (3)

Core 3

Scores

CVSS v3 6.1
EPSS 0.0142
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (1)
hubzilla/hubzilla < 7.2
Published Apr 13, 2022
Tracked Since Feb 18, 2026