Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xcxf-266c-6x5q

Опубликовано: 23 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

EPSS

Процентиль: 54%
0.0031
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
nvd
15 дней назад

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

EPSS

Процентиль: 54%
0.0031
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-434