CVE-2019-25685

Severity CVSS v4.0:
HIGH
Type:
CWE-22 Path Traversal
Publication date:
05/04/2026
Last modified:
09/04/2026

Description

phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:phpbb:phpbb:*:*:*:*:*:*:*:* 3.2.3 (including)