Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-25630

Опубликовано: 24 мар. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:phreesoft:phreebookserp:5.2.3:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00896
Низкий

8.8 High

CVSS3

Дефекты

CWE-434
CWE-434

Связанные уязвимости

CVSS3: 8.8
github
6 месяцев назад

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

EPSS

Процентиль: 58%
0.00896
Низкий

8.8 High

CVSS3

Дефекты

CWE-434
CWE-434
Уязвимость CVE-2019-25630