CVE-2025-46002
MEDIUMsimogeo filemanager <= 2.5.0 - Directory Traversal via filemanager.php Endpoint
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2025-46002. PoCs published by AtT4CKxT3rR0r1ST.
AI-analyzed exploit summary The provided text describes multiple vulnerabilities in Command School Student Management System, including SQL injection, CSRF, XSS, HTML injection, and security bypass. It includes a sample SQL injection payload but lacks functional exploit code.
Description
An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
Exploits (1)
The provided text describes multiple vulnerabilities in Command School Student Management System, including SQL injection, CSRF, XSS, HTML injection, and security bypass. It includes a sample SQL injection payload but lacks functional exploit code.
References (9)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N