CVE-2019-25647 is a high-severity Remote Code Execution (RCE) vulnerability affecting PhreeBooks ERP 5.2.3. Authenticated attackers can exploit a flaw in the image manager to bypass file extension controls, allowing the upload and execution of arbitrary PHP files. With a CVSS score of 8.8, this vulnerability has a network attack vector and low attack complexity, potentially leading to full system compromise through reverse shells and system command execution. While not listed on CISA's KEV catalog and lacking public exploits in common databases like Metasploit or ExploitDB, its critical impact remains significant. Community discussion is minimal, with only one mention identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.2.3CPE matchmatch criteria | cpe:2.3:a:phreesoft:phreebookserp:5.2.3:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.