Medium severity6.2NVD Advisory· Published Mar 24, 2026· Updated Jun 17, 2026
CVE-2019-25632
CVE-2019-25632
Description
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:dulldusk:phpfilemanager:1.7.8:*:*:*:*:*:*:*
- Sourceforge/phpFileManagerv5Range: 1.7.8
Patches
Vulnerability mechanics
References
3- www.exploit-db.com/exploits/46638nvdExploitThird Party AdvisoryVDB Entry
- www.vulncheck.com/advisories/phpfilemanager-local-file-inclusion-via-index-phpnvdThird Party Advisory
- sourceforge.net/projects/phpfm/nvdProduct
News mentions
0No linked articles in our index yet.