CVE-2019-25685 - Vulnerability Analysis
HighCVSS: 8.8Last Updated: April 5, 2026
phpBB - Unrestricted File Upload
Published: April 5, 2026Updated: April 5, 2026Remote Exploitable
Overview
phpBB contains an unrestricted file upload vulnerability caused by exploitation of plupload and phar:// stream wrapper in attachment settings, letting authenticated attackers execute arbitrary code via crafted zip files.
Severity & Score
Severity: High
CVSS Score: 8.8
Impact
Authenticated attackers can upload malicious files leading to remote code execution and full system compromise.
Mitigation
Update to the latest phpBB version with the vulnerability fixed.
References
Related Resources
Details
- CVE ID
- CVE-2019-25685
- Severity
- High
- CVSS Score
- 8.8
- Type
- unrestricted_file_upload
- Status
- new
CWE
- CWE-22
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H