vendor:
PhreeBooks ERP
by:
Besim ALTINOK
9.8
CVSS
HIGH
Remote Command Execution
78
CWE
Product Name: PhreeBooks ERP
Affected Version From: v5.2.4
Affected Version To: v5.2.5
Patch Exists: YES
Related CWE: N/A
CPE: 2.3:a:phreesoft:phreebooks_erp:5.2.5
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Xampp
2020
PhreeBooks ERP 5.2.5 – Remote Command Execution
There are no file extension controls on Image Manager (5.2.4) and on Backup Restore. If an authorized user is obtained, it is possible to run a malicious PHP file on the server.
Mitigation:
Enforce file extension control on Image Manager and Backup Restore.