PT-2026-26930 · I Doit · Doit Cmdb
Ihsan Sencan
·
Published
2026-03-21
·
Updated
2026-03-21
·
CVE-2019-25582
CVSS v3.1
6.5
Medium
| AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file manager=image and supply arbitrary file paths like src/config.inc.php to retrieve configuration files and sensitive system data.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Doit Cmdb