📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2019-25647

High ⚡ Exploit Available
PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension contr
CWE-434 — Weakness Type
Published: Mar 24, 2026  ·  Modified: Mar 30, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

PhreeBooks ERP 5.2.3 contains a remote code execution vulnerability in the image manager that allows authenticated attackers to upload and execute arbitrary PHP files by bypassing file extension controls. Attackers can upload malicious PHP files through the image manager endpoint and execute them to establish reverse shell connections and execute system commands.

🤖 AI Executive Summary

PhreeBooks ERP 5.2.3 contains a critical remote code execution vulnerability in its image manager that allows authenticated attackers to bypass file extension controls and upload malicious PHP files. Exploits are publicly available, enabling attackers to execute arbitrary system commands and establish reverse shells. This vulnerability poses an immediate threat to organizations using this ERP system, particularly those managing financial and operational data.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 01:54
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using PhreeBooks ERP 5.2.3 face critical risk, particularly in: (1) Small to medium-sized enterprises (SMEs) in retail, wholesale, and distribution sectors relying on this ERP for inventory and financial management; (2) Government procurement entities and municipalities using legacy ERP systems; (3) Healthcare facilities managing pharmaceutical inventory and billing; (4) Manufacturing and industrial companies in the Eastern Province. The vulnerability allows complete system compromise, data exfiltration of financial records, customer information, and operational disruption. Organizations subject to SAMA regulations (financial institutions) and NCA cybersecurity requirements face significant compliance violations if exploited.
🏢 Affected Saudi Sectors
Retail and E-commerce Wholesale and Distribution Small and Medium Enterprises (SMEs) Government and Public Administration Healthcare and Pharmaceuticals Manufacturing and Industrial Hospitality and Food Service Education
⚖️ Saudi Risk Score (AI)
9.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all instances of PhreeBooks ERP 5.2.3 in your environment using network scanning and asset inventory tools
2. Restrict access to the image manager endpoint at the firewall/WAF level to authorized users only
3. Implement IP whitelisting for the image manager functionality
4. Disable the image manager feature if not actively used
5. Review access logs for suspicious file uploads or PHP execution attempts

PATCHING GUIDANCE:
1. Upgrade to PhreeBooks ERP version 5.2.4 or later immediately (verify patch availability with vendor)
2. If upgrade is not immediately possible, apply vendor security patches when released
3. Test patches in non-production environment before deployment

COMPENSATING CONTROLS (if patch unavailable):
1. Implement Web Application Firewall (WAF) rules to block PHP file uploads with double extensions (.php.jpg, .phtml, etc.)
2. Configure web server to prevent PHP execution in upload directories (disable PHP execution in /uploads or image directories)
3. Implement strict file type validation on server-side (whitelist only image MIME types: image/jpeg, image/png, image/gif)
4. Enforce file permission restrictions (644 for uploaded files, no execute permissions)
5. Implement comprehensive logging and alerting for image manager activities
6. Conduct daily review of uploaded files for suspicious content

DETECTION RULES:
1. Monitor for POST requests to image manager endpoints with suspicious file extensions
2. Alert on PHP file uploads or execution attempts in image directories
3. Track failed file extension validation attempts
4. Monitor for reverse shell indicators (outbound connections on ports 4444, 5555, 8888, etc.)
5. Log and alert on unusual process execution from web server user context
6. Implement YARA rules to detect PHP webshell patterns in uploaded files
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع نسخ PhreeBooks ERP 5.2.3 في بيئتك باستخدام أدوات المسح والجرد
2. تقييد الوصول إلى نقطة نهاية مدير الصور على مستوى جدار الحماية/WAF للمستخدمين المصرحين فقط
3. تطبيق قائمة بيضاء للعناوين IP لوظيفة مدير الصور
4. تعطيل ميزة مدير الصور إذا لم تكن قيد الاستخدام النشط
5. مراجعة سجلات الوصول للتحقق من محاولات التحميل أو تنفيذ PHP المريبة

إرشادات التصحيح:
1. الترقية إلى PhreeBooks ERP الإصدار 5.2.4 أو أحدث فوراً
2. إذا لم تكن الترقية ممكنة فوراً، طبق تصحيحات الأمان من المورد عند إصدارها
3. اختبر التصحيحات في بيئة غير الإنتاج قبل النشر

عناصر التحكم البديلة:
1. تطبيق قواعد جدار تطبيقات الويب لحظر تحميل ملفات PHP بامتدادات مزدوجة
2. تكوين خادم الويب لمنع تنفيذ PHP في دلائل التحميل
3. تطبيق التحقق الصارم من نوع الملف على جانب الخادم
4. فرض قيود أذونات الملفات (644 للملفات المحملة، بدون أذونات التنفيذ)
5. تطبيق السجلات والتنبيهات الشاملة لأنشطة مدير الصور
6. إجراء مراجعة يومية للملفات المحملة للكشف عن المحتوى المريب

قواعد الكشف:
1. مراقبة طلبات POST إلى نقاط نهاية مدير الصور بامتدادات ملفات مريبة
2. التنبيه على تحميل أو تنفيذ ملفات PHP في دلائل الصور
3. تتبع محاولات التحقق من امتداد الملف الفاشلة
4. مراقبة مؤشرات reverse shell
5. تسجيل والتنبيه على تنفيذ العمليات غير المعتادة
6. تطبيق قواعد YARA للكشف عن أنماط webshell في الملفات المحملة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.4.1 - Event logging and monitoring of system access ECC 2024 A.14.2.1 - Secure development policy and procedures ECC 2024 A.14.2.5 - Secure development environment ECC 2024 A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.BE-1 - Asset management and inventory SAMA CSF PR.AC-1 - Access control and authentication SAMA CSF PR.DS-2 - Data security and protection SAMA CSF DE.CM-1 - Detection and monitoring SAMA CSF RS.RP-1 - Response planning
🟡 ISO 27001:2022
ISO 27001:2022 A.5.23 - Information security for supplier relationships ISO 27001:2022 A.8.1 - User endpoint devices ISO 27001:2022 A.8.3 - Removable media ISO 27001:2022 A.12.2 - Logging ISO 27001:2022 A.12.6 - Management of technical vulnerabilities ISO 27001:2022 A.14.2 - Secure development
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 6.5.1 - Injection flaws prevention PCI DSS 6.5.8 - Improper access control PCI DSS 10.2 - Logging and monitoring PCI DSS 11.3 - Vulnerability scanning
📦 Affected Products / CPE 1 entries
phreesoft:phreebookserp:5.2.3
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-434
Exploit ✓ Yes
Patch ✗ No
Published 2026-03-24
Source Feed nvd
Views 4
🇸🇦 Saudi Risk Score
9.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-434
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.