Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-32807

Опубликовано: 11 апр. 2025
Источник: nvd
CVSS3: 5.3
EPSS Низкий

Описание

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

EPSS

Процентиль: 24%
0.0008
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-24

Связанные уязвимости

CVSS3: 5.3
ubuntu
10 месяцев назад

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

CVSS3: 5.3
debian
10 месяцев назад

A path traversal vulnerability in FusionDirectory before 1.5 allows re ...

CVSS3: 5.3
github
10 месяцев назад

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

EPSS

Процентиль: 24%
0.0008
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-24