PT-2026-26922 · Greencms · Greencms

Ihsan Sencan

·

Published

2026-03-21

·

Updated

2026-03-21

·

CVE-2019-25574

CVSS v3.1

6.5

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2019-25574

Affected Products

Greencms