vendor:
Advanced HRM
by:
Renos Nikolaou
7.5
CVSS
HIGH
Remote Code Execution
78
CWE
Product Name: Advanced HRM
Affected Version From: 1.6
Affected Version To: 1.6
Patch Exists: NO
Related CWE: N/A
CPE: a:coderpixel:advanced_hrm
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Advanced HRM 1.6 – Remote Code Execution
Advanced HRM 1.6 allows users to upload arbitrary files which leads to a remote command execution on the remote server. An attacker can create a php file with malicious code and upload it to the server. Then, the attacker can access the file via the URL and execute the malicious code.
Mitigation:
Restrict access to the server and disable file uploads.