A path traversal vulnerability in FusionDirectory before 1.5 allows remote attackers to read arbitrary files on the host that end with .png (and .svg or .xpm for some configurations) via the icon parameter of a GET request to geticon.php.
CVE ID: CVE-2025-32807
CVSS Base Severity: MEDIUM
CVSS Base Score: 5.3
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Vendor: FusionDirectory
Product: FusionDirectory
EPSS Score: 0.06% (probability of being exploited)
EPSS Percentile: 19.51% (scored less or equal to compared to others)
EPSS Date: 2025-04-20 (when was this score calculated)