PT-2026-27366 · Sourceforge · Phpfilemanager
Murat Kalafatoglu
·
Published
2026-03-24
·
Updated
2026-03-24
·
CVE-2019-25632
CVSS v3.1
6.2
Medium
| AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm current dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Phpfilemanager