CVE-2019-25574

MEDIUM

Green CMS 2.x Path Traversal Arbitrary File Download

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25574. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary The exploit demonstrates an arbitrary file and directory download vulnerability in Green CMS 2.x via two distinct endpoints. The first endpoint allows directory traversal via the 'theme_name' parameter, while the second allows arbitrary file download via a base64-encoded 'id' parameter.

Description

Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/46245

The exploit demonstrates an arbitrary file and directory download vulnerability in Green CMS 2.x via two distinct endpoints. The first endpoint allows directory traversal via the 'theme_name' parameter, while the second allows arbitrary file download via a base64-encoded 'id' parameter.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Green CMS 2.x
Auth required
Prerequisites: Valid session cookies for authentication
devstral-2 · analyzed Mar 21, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46245
https://www.exploit-db.com/exploits/46245
Product product
Official Product Homepage
http://www.greencms.net/
Product product
Product Reference
https://codeload.github.com/GreenCMS/GreenCMS/zip/beta
Third Party Advisory third-party-advisory
VulnCheck Advisory: Green CMS 2.x Path Traversal Arbitrary File Download
https://www.vulncheck.com/advisories/green-cms-2-x-path-traversal-arbitrary-file-download

Scores

CVSS v3 6.5
EPSS 0.0110
EPSS Percentile 61.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
Greencms/Green CMS 2.0
njtech/greencms 2.1.0612 - 2.3.0603
Published Mar 21, 2026
Tracked Since Mar 21, 2026