CVE-2025-32807

MEDIUM

FusionDirectory <1.5 - Path Traversal

Title source: llm
STIX 2.1

Description

A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.

Scores

CVSS v3 5.3
EPSS 0.0028
EPSS Percentile 51.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-24
Status published
Products (1)
FusionDirectory/FusionDirectory < 1.5
Published Apr 11, 2025
Tracked Since Feb 18, 2026