A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 10 Apr 2025 23:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php. | |
Weaknesses | CWE-24 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-11T16:04:04.886Z
Reserved: 2025-04-10T00:00:00.000Z
Link: CVE-2025-32807

Updated: 2025-04-11T15:59:14.277Z

Status : Awaiting Analysis
Published: 2025-04-11T00:15:27.777
Modified: 2025-04-11T15:39:52.920
Link: CVE-2025-32807

No data.