CVE-2017-6090

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute...

Basic Information

CVE State
PUBLISHED
Reserved Date
February 18, 2017
Published Date
October 02, 2017
Last Updated
August 05, 2024
Vendor
PhpCollab
Product
PhpCollab
Description
Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.
Tags
nuclei_scanner php

CVSS Scores

CVSS v3.0

8.8 - HIGH

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2.0

6.5

Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

EPSS Score

Score
84.99% (Percentile: 99.29%) as of 2025-07-29

Exploit Status

Exploited in the Wild
Yes (2025-07-05 00:00:00 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-07-06 12:00:35 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

phpcollab_upload_exec

Type: metasploit • Created: Unknown

Metasploit module for CVE-2017-6090

jlk/exploit-CVE-2017-6090

Type: github • Created: 2018-02-17 01:07:58 UTC • Stars: 1

Containerized exploitable PhpCollab

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel