Home

Description

An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.

PUBLISHED Reserved 2025-04-22 | Published 2025-07-18 | Updated 2025-07-23 | Assigner mitre

References

github.com/...ist/blob/main/CVE-2025-46001/CVE-2025-46001.md exploit

github.com/simogeo/Filemanager

www.exploit-db.com/exploits/38895

github.com/...ist/blob/main/CVE-2025-46001/CVE-2025-46001.md

cve.org (CVE-2025-46001)

nvd.nist.gov (CVE-2025-46001)

Download JSON