CVE-2022-27257: High severity hubzilla vulnerability
A PHP Local File Inclusion vulneraility in the default Redbasic theme for Hubzilla before version 7.2 allows remote attackers to include arbitrary php files via the schema parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-27257?
CVE-2022-27257 is a PHP Local File Inclusion vulnerability in the default Redbasic theme for Hubzilla before version 7.2.
What is the severity of CVE-2022-27257?
The severity of CVE-2022-27257 is high, with a severity value of 7.5.
How does CVE-2022-27257 affect Hubzilla?
CVE-2022-27257 affects Hubzilla versions before 7.2 and allows remote attackers to include arbitrary PHP files via the schema parameter.
How can I fix CVE-2022-27257?
To fix CVE-2022-27257, it is recommended to update to Hubzilla version 7.2 or a later version.
Where can I find more information about CVE-2022-27257?
More information about CVE-2022-27257 can be found at the following references: [Reference 1](https://framagit.org/hubzilla/core/-/commit/0784cd593a39a4fc297e8a82f7e79bc8019a0868#1c497fbb3a46b78edf04cc2a2fa33f67e3ffbe2a), [Reference 2](https://hubzilla.org/channel/hubzilla/)