CVE-2019-25574
Severity CVSS v4.0:
HIGH
Type:
CWE-22
Path Traversal
Publication date:
21/03/2026
Last modified:
24/03/2026
Description
Green CMS 2.x contains a path traversal vulnerability that allows authenticated attackers to download arbitrary files and directories by injecting directory traversal sequences. Attackers can manipulate the theme_name parameter in the themeexporthandle action or supply base64-encoded file paths to the downfile action to retrieve sensitive files outside intended directories.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:njtech:greencms:*:*:*:*:*:*:*:* | 2.1.0612 (including) | 2.3.0603 (including) |
To consult the complete list of CPE names with products and versions, see this page



