Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 24 Mar 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Njtech
Njtech greencms |
|
| CPEs | cpe:2.3:a:njtech:greencms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Njtech
Njtech greencms |
Mon, 23 Mar 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 23 Mar 2026 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Greencms
Greencms greencms |
|
| Vendors & Products |
Greencms
Greencms greencms |
Sat, 21 Mar 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories. | |
| Title | Green CMS 2.x Path Traversal Arbitrary File Download | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-03-23T16:36:16.889Z
Reserved: 2026-03-21T15:23:41.589Z
Link: CVE-2019-25574
Updated: 2026-03-23T16:36:04.403Z
Status : Analyzed
Published: 2026-03-21T16:16:00.960
Modified: 2026-03-24T16:37:42.487
Link: CVE-2019-25574
No data.
OpenCVE Enrichment
Updated: 2026-03-25T14:47:09Z