Unrated severityNVD Advisory· Published Mar 21, 2026· Updated Mar 23, 2026
Green CMS 2.x Path Traversal Arbitrary File Download
CVE-2019-25574
Description
Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- www.exploit-db.com/exploits/46245mitreexploit
- www.vulncheck.com/advisories/green-cms-2-x-path-traversal-arbitrary-file-downloadmitrethird-party-advisory
- www.greencms.netmitreproduct
- codeload.github.com/GreenCMS/GreenCMS/zip/betamitreproduct
News mentions
0No linked articles in our index yet.