High severity7.5OSV Advisory· Published Dec 17, 2025· Updated Jun 17, 2026
CVE-2025-67174
CVE-2025-67174
Description
A local file inclusion (LFI) vulnerability in RiteCMS v3.1.0 allows attackers to read arbitrary files on the host via a directory traversal in the admin_language_file and default_page_language_file in the admin.php component
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
3- github.com/mbiesiad/vulnerability-research/tree/main/CVE-2025-67174nvdExploitThird Party Advisory
- github.com/handylulu/RiteCMS/blob/master/admin.phpnvdProduct
- github.com/handylulu/RiteCMS/blob/master/cms/subtemplates/settings.inc.tplnvdProduct
News mentions
0No linked articles in our index yet.