CVE-2017-6090

High PUBLISHED

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute...

Vendor: PhpCollab Product: PhpCollab

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
High
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
8.8 High EPSS 96.1%

At a Glance

Unrestricted file upload vulnerability in clients/editclient.php in PhpCollab 2.5.1 and earlier allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in logos_clients/.

nuclei_scanner
CVE Published
Oct 02, 2017
Exploitation Reported
Jun 10, 2026
CVSS
8.8 High
EPSS
96.1%
Remote Low complexity No user interaction

CVE References