
CVE-2019-25471 FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint… https://www.cve.org/CVERecord?id=CVE-2019-25471
Post summary
The post documents a CVE-2019-25471 arbitrary file‑upload flaw in FileThingie 2.5.7, noting how attackers can exploit it by sending ZIP archives to ft2.php, but provides no PoC, exploit, or mitigation details.


