Dismissed
Permalink
CVE-2025-64363
7.5 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): HIGH
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
by @pyrox0 Activity log
- Created automatic suggestion
- @pyrox0 dismissed
WordPress Kleo theme < 5.5.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in SeventhQueen Kleo kleo allows PHP Local File Inclusion.This issue affects Kleo: from n/a through < 5.5.0.
References
- https://vdp.patchstack.com/database/Wordpress/Theme/kleo/vulnerability/wordpres… vdb-entry
- https://vdp.patchstack.com/database/Wordpress/Theme/kleo/vulnerability/wordpres… vdb-entry
- https://vdp.patchstack.com/database/Wordpress/Theme/kleo/vulnerability/wordpres… vdb-entry
- https://patchstack.com/database/Wordpress/Theme/kleo/vulnerability/wordpress-kl… vdb-entry
Affected products
kleo
- =<< 5.5.0
Matching in nixpkgs
pkgs.libsForQt5.libkleo
None
pkgs.kdePackages.libkleo
Library that provides cryptography support for mails
pkgs.libsForQt5.kleopatra
Certificate manager and unified crypto GUI
pkgs.kdePackages.kleopatra
Certificate manager and GUI for OpenPGP and CMS cryptography
pkgs.plasma5Packages.libkleo
None
pkgs.plasma5Packages.kleopatra
Certificate manager and unified crypto GUI
Package maintainers
-
@K900 Ilya K. <me@0upti.me>
-
@ttuegel Thomas Tuegel <ttuegel@mailbox.org>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@vandenoever Jos van den Oever <jos@vandenoever.info>