An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
{ "github_reviewed": true, "github_reviewed_at": "2025-07-20T16:44:46Z", "nvd_published_at": "2025-07-18T14:15:24Z", "cwe_ids": [ "CWE-23" ], "severity": "MODERATE" }