Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-47904

Опубликовано: 23 янв. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

EPSS

Процентиль: 57%
0.00347
Низкий

8.8 High

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 8.8
github
15 дней назад

PhreeBooks 5.2.3 contains an authenticated file upload vulnerability in the Image Manager that allows remote code execution. Attackers can upload a malicious PHP web shell by exploiting unrestricted file type uploads to gain command execution on the server.

EPSS

Процентиль: 57%
0.00347
Низкий

8.8 High

CVSS3

Дефекты

CWE-434