An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format.
History

Fri, 19 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-706
CPEs cpe:2.3:a:easyimages2.0_project:easyimages2.0:*:*:*:*:*:*:*:*

Thu, 18 Dec 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-434
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 11 Dec 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Easyimages2.0 Project
Easyimages2.0 Project easyimages2.0
Vendors & Products Easyimages2.0 Project
Easyimages2.0 Project easyimages2.0

Thu, 11 Dec 2025 16:45:00 +0000

Type Values Removed Values Added
Description An arbitrary file rename vulnerability in the /admin/manager.php component of EasyImages 2.0 v2.8.6 and below allows attackers to execute arbitrary code via renaming a PHP file to a SVG format.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2025-12-18T20:52:55.502Z

Reserved: 2025-11-18T00:00:00.000Z

Link: CVE-2025-65474

cve-icon Vulnrichment

Updated: 2025-12-15T17:55:08.778Z

cve-icon NVD

Status : Analyzed

Published: 2025-12-11T17:15:58.127

Modified: 2025-12-19T19:46:51.357

Link: CVE-2025-65474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-12-11T21:37:26Z