PT-2026-27364 · Unknown · Phreebookserp

Abdullah Çelebi

·

Publicado

2026-03-24

·

Atualizado

2026-03-24

·

CVE-2019-25630

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PhreeBooks ERP version 5.2.3
Description The software contains a flaw in the Image Manager component that allows authenticated attackers to upload malicious files. Attackers can submit requests to the image upload endpoint, specifically uploading PHP files through the imgFile parameter to the ''bizuno/image/manager'' endpoint. These uploaded files can then be executed via the ''bizunoFS.php'' script, leading to remote code execution.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Correção

Unrestricted File Upload

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-25630

Produtos afetados

Phreebookserp