What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Mags mags.This issue affects Mags: from n/a through <= 1.1.6.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
What the vulnerability does
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehorse Mags mags.This issue affects Mags: from n/a through <= 1.1.6.
Explanation of Vulnerability in Simple Terms
Mags versions 1.1.6 and earlier contain a vulnerability that allows an attacker to read sensitive data, modify site content, or disrupt service. The attack requires network access and user interaction—typically the victim must click a malicious link or visit a compromised page. The vulnerability affects confidentiality, integrity, and availability of the site.
What an attacker can do
Read sensitive data, modify site content, or cause the site to become unavailable.
Potential impact on your site
Site data could be exposed, content altered, or service disrupted without admin action needed.
Conditions required to exploit
Victim must click a malicious link or visit an attacker-controlled page; no login required.
Key dates
External resources
Related vulnerabilities