Sourceforge · Phpfilemanager · CVE-2019-25632
**Name of the Vulnerable Software and Affected Versions**
phpFileManager version 1.7.8
**Description**
A local file inclusion issue allows unauthenticated attackers to read arbitrary files from the server. This is achieved by sending crafted GET requests to the 'index.php' endpoint by manipulating the `action`, `fm current dir`, and `filename` parameters. This can lead to the exposure of sensitive system files, such as /etc/passwd.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.