CVE-2019-25630
HIGHPhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25630. PoCs published by Abdullah Çelebi.
AI-analyzed exploit summary The exploit demonstrates an arbitrary file upload vulnerability in PhreeBooks ERP v5.2.3, allowing an attacker to upload a malicious PHP file via the Image Manager tool and achieve remote code execution (RCE). The PoC includes the specific HTTP request and file upload mechanism used to exploit the vulnerability.
Description
PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.
Exploits (1)
The exploit demonstrates an arbitrary file upload vulnerability in PhreeBooks ERP v5.2.3, allowing an attacker to upload a malicious PHP file via the Image Manager tool and achieve remote code execution (RCE). The PoC includes the specific HTTP request and file upload mechanism used to exploit the vulnerability.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H