CVE-2025-2032: 1000mz Chestnutcms
Low severity, CVSS 3.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability classified as problematic was found in ChestnutCMS 1.5.2. This vulnerability affects the function renameFile of the file /cms/file/rename. The manipulation of the argument rename leads to path traversal. The exploit has been disclosed to the public and may be used.
Affected products
- 1000mz Chestnutcms: version 1.5.2 only
Published 2025-03-06. Last modified 2026-06-17.