CVE-2019-25630

HIGH

PhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager

Title source: cna
STIX 2.1

Description

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

Exploits (1)

exploitdb WORKING POC
by Abdullah Çelebi · textwebappsphp
https://www.exploit-db.com/exploits/46644

References (4)

Core 4
Core References
Exploit exploit
ExploitDB-46644
https://www.exploit-db.com/exploits/46644
Product product
Official Product Homepage
https://www.phreesoft.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: PhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager
https://www.vulncheck.com/advisories/phreebooks-erp-arbitrary-file-upload-via-image-manager

Scores

CVSS v3 8.8
EPSS 0.0077
EPSS Percentile 73.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (2)
Phreesoft/PhreeBooks ERP 5.2.3
phreesoft/phreebookserp 5.2.3
Published Mar 24, 2026
Tracked Since Mar 24, 2026