An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
https://www.exploit-db.com/exploits/38895
https://github.com/zakumini/CVE-List/blob/main/CVE-2025-46001/CVE-2025-46001.md