Unknown · Fusiondirectory · CVE-2025-32807
Name of the Vulnerable Software and Affected Versions:
FusionDirectory versions prior to 1.5
Description:
A path traversal vulnerability in FusionDirectory allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the `icon` parameter of a GET request to "geticon.php".
Recommendations:
For versions prior to 1.5, update to version 1.5 or later to resolve the issue.
As a temporary workaround, consider restricting access to the "geticon.php" endpoint or disabling the `icon` parameter until a patch is applied.