CVE-2025-32807: Fusiondirectory
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.
Affected products
- Fusiondirectory Fusiondirectory: before 1.5 (fixed in 1.5)
Published 2025-04-11. Last modified 2026-06-17.