CVE-2019-25471 identifies a critical arbitrary file upload vulnerability in FileThingie 2.5.7. This flaw allows unauthenticated attackers to upload malicious ZIP archives containing PHP shells via the ft2.php endpoint. Upon extraction, these shells can be used to execute arbitrary commands, leading to a complete compromise of confidentiality, integrity, and availability. Rated with a CVSS score of 9.8 (Critical), it presents a low-complexity network attack vector requiring no privileges or user interaction. Currently, there is no evidence of active exploitation, public exploit code, or significant community attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.5.7CPE matchmatch criteria | cpe:2.3:a:leefish:file_thingie:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.