MEDIUM6.5
GHSA-r7q6-6fmq-mx4c
Filemanager is vulnerable to Relative Path Traversal through filemanager.php
Details
An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/simogeo/filemanager
Introduced in:
0No fixed version published yet for simogeo/filemanager (composer). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-46002[ADVISORY]
- https://github.com/simogeo/Filemanager[PACKAGE]
- https://github.com/simogeo/Filemanager/releases/tag/v1.7.0[WEB]
- https://github.com/simogeo/Filemanager/releases/tag/v1.8.0[WEB]
- https://github.com/simogeo/Filemanager/releases/tag/v2.0.0[WEB]
- https://github.com/simogeo/Filemanager/releases/tag/v2.1.0[WEB]
- https://github.com/simogeo/Filemanager/releases/tag/v2.2.0[WEB]
- https://github.com/simogeo/Filemanager/releases/tag/v2.3.0[WEB]
- https://github.com/zakumini/CVE-List/blob/main/CVE-2025-46002/CVE-2025-46002.md[WEB]
- https://www.exploit-db.com/exploits/38945[WEB]