phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.
References
| Link | Resource |
|---|---|
| https://www.exploit-db.com/exploits/46512 | Exploit VDB Entry |
| https://www.vulncheck.com/advisories/phpbb-arbitrary-file-upload-via-phar-deserialization | Third Party Advisory |
Configurations
History
09 Apr 2026, 19:07
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:phpbb:phpbb:*:*:*:*:*:*:*:* | |
| First Time |
Phpbb
Phpbb phpbb |
|
| References | () https://www.exploit-db.com/exploits/46512 - Exploit, VDB Entry | |
| References | () https://www.vulncheck.com/advisories/phpbb-arbitrary-file-upload-via-phar-deserialization - Third Party Advisory |
05 Apr 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-05 21:16
Updated : 2026-04-09 19:07
NVD link : CVE-2019-25685
Mitre link : CVE-2019-25685
CVE.ORG link : CVE-2019-25685
JSON object : View
Products Affected
phpbb
- phpbb
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
