vendor:
PhreeBooks ERP
by:
Abdullah Çelebi
7.5
CVSS
HIGH
Arbitrary File Upload
434
CWE
Product Name: PhreeBooks ERP
Affected Version From: 5.2.3
Affected Version To: 5.2.3
Patch Exists: NO
Related CWE: N/A
CPE: a:phreesoft:phreebooks:5.2.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: WAMPP @Win
2019
PhreeBooks ERP v5.2.3 – Arbitrary File Upload
An attacker could run a remote code after an authorized user login using the parameter.
Mitigation:
Ensure that the application is not vulnerable to arbitrary file uploads.