A vulnerability has been discovered in Frei-Chat, which can be exploited by malicious people to compromise a vulnerable system.
The vulnerability is caused due to the client/plugins/upload/upload.php script not properly validating uploaded files, which can be exploited to execute arbitrary PHP code by uploading a PHP file with an allowed MIME media type e.g. image/jpeg.
The vulnerability is confirmed in version 7.2. Other versions may also be affected.