CVE-2019-25647 HIGH

CVE-2019-25647: PhreeBooks ERP 5.2.3 Remote Code Execution via Image Manager

Vendor Phreesoft
Product PhreeBooks ERP
Weakness CWE-434 · Unrestricted file upload
Published March 24, 2026
Last update March 24, 2026

CVSS base score

8.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse shell connections and execute system commands.

Key dates

02Disclosure timeline

March 24, 2026 CVE published
March 24, 2026 Record updated