PhreeBooks
cpe:2.3:a:phreesoft:phreebookserp:*:*:*:*:*:*:*
- 5.2.3
A remote code execution vulnerability has been identified in PhreeBooks version 5.2.3. This issue arises from an authenticated file upload vulnerability in the Image Manager, which allows attackers to upload a malicious PHP web shell. The vulnerability exploits unrestricted file type uploads, enabling command execution on the server.
Exploitation of this vulnerability allows for remote code execution on the server where PhreeBooks 5.2.3 is installed.
To reproduce this vulnerability, an authenticated user must upload a file through the Image Manager. The application does not restrict file types, allowing the upload of a PHP file containing a web shell payload. Once the file is uploaded, it can be accessed via the web, executing the embedded commands on the server.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.