CVE-2025-15187 | GreenCMS up to 2.3 File DataController.class.php sqlFiles/zipFiles path traversal (EUVD-2025-205573)
A vulnerability identified as critical has been detected in GreenCMS up to 2.3. This affects an unknown part of the file /DataController.class.php of the component File Handler. Performing manipulation of the argument sqlFiles/zipFiles results in path traversal. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is identified as CVE-2025-15187. The attack can be initiated remotely. Additionally, an exploit exists.