Unrated severityNVD Advisory· Published Mar 24, 2026· Updated Mar 26, 2026
phpFileManager 1.7.8 Local File Inclusion via index.php
CVE-2019-25632
Description
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd from the server.
Affected products
2- Range: =1.7.8
- Sourceforge/phpFileManagerv5Range: 1.7.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.exploit-db.com/exploits/46638mitreexploit
- www.vulncheck.com/advisories/phpfilemanager-local-file-inclusion-via-index-phpmitrethird-party-advisory
- sourceforge.net/projects/phpfm/mitreproduct
News mentions
0No linked articles in our index yet.