CVE-2025-46002

An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
Configurations

Configuration 1 (hide)

cpe:2.3:a:simogeo:filemanager:*:*:*:*:*:*:*:*

History

14 Oct 2025, 14:22

Type Values Removed Values Added
References () https://github.com/simogeo/Filemanager - () https://github.com/simogeo/Filemanager - Product
References () https://github.com/simogeo/Filemanager/releases/tag/v1.7.0 - () https://github.com/simogeo/Filemanager/releases/tag/v1.7.0 - Release Notes
References () https://github.com/simogeo/Filemanager/releases/tag/v1.8.0 - () https://github.com/simogeo/Filemanager/releases/tag/v1.8.0 - Release Notes
References () https://github.com/simogeo/Filemanager/releases/tag/v2.0.0 - () https://github.com/simogeo/Filemanager/releases/tag/v2.0.0 - Release Notes
References () https://github.com/simogeo/Filemanager/releases/tag/v2.1.0 - () https://github.com/simogeo/Filemanager/releases/tag/v2.1.0 - Release Notes
References () https://github.com/simogeo/Filemanager/releases/tag/v2.2.0 - () https://github.com/simogeo/Filemanager/releases/tag/v2.2.0 - Release Notes
References () https://github.com/simogeo/Filemanager/releases/tag/v2.3.0 - () https://github.com/simogeo/Filemanager/releases/tag/v2.3.0 - Release Notes
References () https://github.com/zakumini/CVE-List/blob/main/CVE-2025-46002/CVE-2025-46002.md - () https://github.com/zakumini/CVE-List/blob/main/CVE-2025-46002/CVE-2025-46002.md - Exploit, Third Party Advisory
References () https://www.exploit-db.com/exploits/38945 - () https://www.exploit-db.com/exploits/38945 - Third Party Advisory
First Time Simogeo filemanager
Simogeo
CPE cpe:2.3:a:simogeo:filemanager:*:*:*:*:*:*:*:*

22 Jul 2025, 13:06

Type Values Removed Values Added
Summary
  • (es) Un problema en Filemanager v2.5.0 y anteriores permite a los atacantes ejecutar un directory traversal mediante el envío de una solicitud HTTP manipulada al endpoint filemanager.php.

18 Jul 2025, 19:15

Type Values Removed Values Added
CWE CWE-23
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5

18 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-18 14:15

Updated : 2025-10-14 14:22


NVD link : CVE-2025-46002

Mitre link : CVE-2025-46002

CVE.ORG link : CVE-2025-46002


JSON object : View

Products Affected

simogeo

  • filemanager
CWE
CWE-23

Relative Path Traversal