CVE-2019-25630

HIGH

PhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-25630. PoCs published by Abdullah Çelebi.

AI-analyzed exploit summary The exploit demonstrates an arbitrary file upload vulnerability in PhreeBooks ERP v5.2.3, allowing an attacker to upload a malicious PHP file via the Image Manager tool and achieve remote code execution (RCE). The PoC includes the specific HTTP request and file upload mechanism used to exploit the vulnerability.

Description

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

Exploits (1)

exploitdb WORKING POC
by Abdullah Çelebi · textwebappsphp
https://www.exploit-db.com/exploits/46644

The exploit demonstrates an arbitrary file upload vulnerability in PhreeBooks ERP v5.2.3, allowing an attacker to upload a malicious PHP file via the Image Manager tool and achieve remote code execution (RCE). The PoC includes the specific HTTP request and file upload mechanism used to exploit the vulnerability.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: PhreeBooks ERP v5.2.3
Auth required
Prerequisites: Authenticated access to the PhreeBooks ERP application · Access to the Image Manager tool
devstral-2 · analyzed Mar 24, 2026 Full analysis →

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46644
https://www.exploit-db.com/exploits/46644
Product product
Official Product Homepage
https://www.phreesoft.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: PhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager
https://www.vulncheck.com/advisories/phreebooks-erp-arbitrary-file-upload-via-image-manager

Scores

CVSS v3 8.8
EPSS 0.0090
EPSS Percentile 55.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
Phreesoft/PhreeBooks ERP 5.2.3
phreesoft/phreebookserp 5.2.3
Published Mar 24, 2026
Tracked Since Mar 24, 2026