CVE-2025-32807
EUVD-2025-1071311.04.2025, 00:15
A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| fusiondirectory | fusiondirectory | 𝑥 < 1.5 | CNA |
Ubuntu Releases
References