CVE-2019-25574
MEDIUMGreen CMS 2.x Path Traversal Arbitrary File Download
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25574. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file and directory download vulnerability in Green CMS 2.x via two distinct endpoints. The first endpoint allows directory traversal via the 'theme_name' parameter, while the second allows arbitrary file download via a base64-encoded 'id' parameter.
Description
Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.
Exploits (1)
The exploit demonstrates an arbitrary file and directory download vulnerability in Green CMS 2.x via two distinct endpoints. The first endpoint allows directory traversal via the 'theme_name' parameter, while the second allows arbitrary file download via a base64-encoded 'id' parameter.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N