PT-2026-27364 · Unknown · Phreebookserp
Abdullah Çelebi
·
Published
2026-03-24
·
Updated
2026-03-24
·
CVE-2019-25630
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PhreeBooks ERP version 5.2.3
Description
The software contains a flaw in the Image Manager component that allows authenticated attackers to upload malicious files. Attackers can submit requests to the image upload endpoint, specifically uploading PHP files through the
imgFile parameter to the ''bizuno/image/manager'' endpoint. These uploaded files can then be executed via the ''bizunoFS.php'' script, leading to remote code execution.Recommendations
Update to a newer version that contains a fix for this vulnerability.
Exploit
Fix
Unrestricted File Upload
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Phreebookserp