CVE-2019-25630 HIGH

CVE-2019-25630: PhreeBooks ERP 5.2.3 Arbitrary File Upload via Image Manager

Vendor Phreesoft
Product PhreeBooks ERP
Weakness CWE-434 · Unrestricted file upload
Published March 24, 2026
Last update March 26, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

PhreeBooks ERP 5.2.3 contains an arbitrary file upload vulnerability in the Image Manager component that allows authenticated attackers to upload malicious files by submitting requests to the image upload endpoint. Attackers can upload PHP files through the imgFile parameter to the bizuno/image/manager endpoint and execute them via the bizunoFS.php script for remote code execution.

Key dates

02Disclosure timeline

March 24, 2026 CVE published
March 26, 2026 Record updated

Related vulnerabilities

04Related CVE