The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the attacker can upload executable content (e.g., asp or aspx) for executing OS commands on the server.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-6198 The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the attacker can upload executable content (e.g., asp or aspx) for executing OS commands on the server.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-05T00:34:53.330Z

Reserved: 2019-08-17T00:00:00

Link: CVE-2019-15130

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-08-18T17:15:09.713

Modified: 2024-11-21T04:28:06.990

Link: CVE-2019-15130

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.