CVE-2025-31340 PUBLISHED

Wisdom Master Pro - Improper Control of Filename for Include/Require Statement in PHP Program

Assigner: ZUSO ART
Reserved: 28.03.2025 Published: 17.04.2025 Updated: 17.04.2025

A improper control of filename for include/require statement in PHP program vulnerability in the retrieve course Information function of Wisdom Master Pro versions 5.0 through 5.2 allows remote attackers to perform arbitrary system commands by running a malicious file.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H
CVSS Score: 9.9

Product Status

Vendor SUNNET Technology Co., Ltd.
Product Wisdom Master Pro
Versions Default: affected
  • affected from 5.0 to 5.2 (incl.)

References

Problem Types

  • CWE-98: Improper Control of Filename for Include/Require Statement in PHP Program CWE