Back to all
2024-08-05

Hamastar MeetingHub Paperless Meetings - Unrestricted Upload of File with Dangerous Type

ZUSOART ID
ZA-2024-02
CVE ID
CVE-2024-6117
Vulnerability Type
CWE-434: Unrestricted Upload of File with Dangerous Type
CVSS 4.0 Base
9.3
Description

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

Vendor
Hamastar Technology
Product
Category
Version affected
MeetingHub Paperless Meetings
2021
Mitigations

Contact Hamastar Technology for version updates.

Release date
2024-08-05
Credit

Yen Chun Shen (YC Shen) of ZUSO ART