โ† Back to all CVEs

CVE-2019-25579

HIGH codnloc NVD
CVSS Score 7.5
Severity HIGH
Published Mar 21, 2026
Vendor codnloc

Description

phpTransformer 2016.9 contains a directory traversal vulnerability that allows unauthenticated attackers to access arbitrary files by manipulating the path parameter. Attackers can send requests to the jQueryFileUploadmaster server endpoint with traversal sequences ../../../../../../ to list and retrieve files outside the intended directory.

References