Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-32807


A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.


Published

2025-04-11T00:15:27.777

Last Modified

2025-04-11T15:39:52.920

Status

Awaiting Analysis

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-24

Affected Vendors & Products

-


References