Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25574

Опубликовано: 21 мар. 2026
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:njtech:greencms:*:*:*:*:*:*:*:*
Версия от 2.1.0612 (включая) до 2.3.0603 (включая)

EPSS

Процентиль: 62%
0.01101
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 6.5
github
4 месяца назад

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

EPSS

Процентиль: 62%
0.01101
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-22