CVE-2025-46001
18.07.2025, 14:15
An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.Enginsight
Vendor | Product | Version |
---|---|---|
simogeo | filemanager | 0.8 ≤ 𝑥 ≤ 1.1 |
simogeo | filemanager | 1.5.0 ≤ 𝑥 ≤ 2.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration