Looking for the vulnerability index of Invicti's legacy products?
phpBB Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2019-25685 - Vulnerability Database

phpBB Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability - CVE-2019-25685

High
Reference: CVE-2019-25685
Title: phpBB Improper Limitation of a Pathname to a Restricted Directory (Path Traversal) Vulnerability
Overview:

phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper. Attackers can upload a crafted zip file containing serialized PHP objects that execute arbitrary code when deserialized through the imagick parameter in attachment settings.