High-severity vulnerabilities have been disclosed for PhreeBooks ERP 5.2.3 and phpBB, both allowing authenticated attackers to turn file upload functionality into remote code execution. In CVE-2019-25630, an attacker can abuse the imgFile parameter in the bizuno/image/manager endpoint to upload a malicious PHP file and then execute it through bizunoFS.php. The issue affects the Image Manager component in PhreeBooks ERP and was rated high impact under both CVSS v3.1 and v4.0.
A separate flaw, CVE-2019-25685, affects phpBB and uses plupload together with the phar:// stream wrapper to upload a crafted ZIP archive containing serialized PHP objects. When those objects are later deserialized via the imagick parameter in attachment settings, arbitrary code can be executed on the server. References tied to the disclosures include Exploit-DB and VulnCheck, indicating public technical detail is available for both upload-to-RCE attack paths.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A CVE entry described an authenticated phpBB vulnerability involving plupload abuse, a crafted ZIP archive, and phar deserialization through attachment settings, enabling remote code execution. The record states the CVE was received by disclosure@vulncheck.com on this date and cites Exploit-DB and VulnCheck references.
A CVE entry documented an authenticated arbitrary file upload vulnerability in PhreeBooks ERP 5.2.3's Image Manager that can lead to remote code execution via uploaded PHP files. The record notes the CVE was received by disclosure@vulncheck.com on this date and references supporting advisories and exploit sources.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.