CVE-2025-32807

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.
Configurations

No configuration.

History

No history.

Information

Published : 2025-04-11 00:15

Updated : 2025-04-11 15:39


NVD link : CVE-2025-32807

Mitre link : CVE-2025-32807

CVE.ORG link : CVE-2025-32807


JSON object : View

Products Affected

No product.

CWE
CWE-24

Path Traversal: '../filedir'