NONE · 0

CVE-2025-0632

Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor coul...

Vulnerability Description

Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor could execute malicious scripts to automatically download configuration files in known locations to exfiltrate data including credentials, and with no rate limiting a malicious actor could enumerate the filesystem of the host machine and potentially lead to full host compromise. This issue affects Rock Maker Web: from 3.2.1.1 and later

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-0632?

CVE-2025-0632 is a documented vulnerability. Local File Inclusion (LFI) vulnerability in a Render function of Formulatrix Rock Maker Web (RMW) allows a remote attacker to obtain sensitive data via arbitrary code execution. A malicious actor coul...

How severe is CVE-2025-0632?

CVSS scoring is not yet available for CVE-2025-0632. Check NVD for updates.

Is there a patch for CVE-2025-0632?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.