CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-22145: Carbon has an arbitrary file include via unvalidated input passed to Carbon::setLocale

6.3 CVSS

Description

Carbon is an international PHP extension for DateTime. Application passing unsanitized user input to Carbon::setLocale are at risk of arbitrary file include, if the application allows users to upload files with .php extension in an folder that allows include or require to read it, then they are at risk of arbitrary code ran on their servers. This vulnerability is fixed in 3.8.4 and 2.72.6.

Classification

CVE ID: CVE-2025-22145

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.3

Affected Products

Vendor: CarbonPHP

Product: carbon

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-06 (when was this score calculated)

References

https://github.com/CarbonPHP/carbon/security/advisories/GHSA-j3f9-p6hm-5w6q
https://github.com/briannesbitt/Carbon/commit/129700ed449b1f02d70272d2ac802357c8c30c58

Timeline