VYPR

Packagist (Composer) package

simogeo/filemanager

pkg:composer/simogeo/filemanager

Vulnerabilities (2)

  • CVE-2025-46002MedJul 18, 2025
    affected <= 2.5.0

    An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.

  • CVE-2025-46001CriJul 18, 2025
    affected >= 0

    An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.