CVE detail
CVE-2019-25582 — CVE-2019-25582
Published 2026-03-21 · Modified 2026-06-17 · Vendor i-doit · Product i-doit · Source nvd
MEDIUM
severity
CVSS-derived band
0.0037
EPSS probability
exploitation probability, 30d
30.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
i-doit CMDB 1.12 contains an arbitrary file download vulnerability that allows authenticated attackers to download sensitive files by manipulating the file parameter in index.php. Attackers can send GET requests to index.php with file_manager=image and supply arbitrary file paths like src/config.inc.php to retrieve configuration files and sensitive system data.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References