Arbitrary File Upload Vulnerability in phpBB by phpBB Group
CVE-2019-25685
Key Information:
Badges
What is CVE-2019-25685?
The phpBB software is susceptible to an arbitrary file upload vulnerability due to the exploitation of the plupload functionality and phar:// stream wrapper. Authenticated attackers can leverage this vulnerability by uploading maliciously crafted zip files that contain serialized PHP objects. These objects are executed as arbitrary code upon deserialization through the imagick parameter in the attachment settings, leading to potential unauthorized access and compromise of the affected system.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
phpBB 3.2.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
