PT-2025-16015 · Unknown+1 · Fusiondirectory+1

Dockx

+1

·

Published

2025-04-10

·

Updated

2025-04-11

·

CVE-2025-32807

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions: FusionDirectory versions prior to 1.5
Description: A path traversal vulnerability in FusionDirectory allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to "geticon.php".
Recommendations: For versions prior to 1.5, update to version 1.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the "geticon.php" endpoint or disabling the icon parameter until a patch is applied.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-32807

Affected Products

Debian
Fusiondirectory