Security Advisory
CVE-2025-22213
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
Inadequate checks in the Media Manager allowed users with "edit" privileges to change file extension to arbitrary extension, including .php and other potentially executable extensions.