LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2019-25630

phreesoft · phreebookserp

Published
CVSS8.8
Severityhigh
WeaknessCWE-434
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

References

← Back to the CVE Tracker

Our coverage of CVE-2019-25630

No stories yet. This page updates automatically when we publish reporting that references CVE-2019-25630.