Impact
Redsea Cloud eHR suffers from an unauthenticated arbitrary file upload weakness that lets attackers send a multipart POST request to the PtFjk.mob servlet endpoint with a file whose MIME type is spoofed as image/jpeg but actually contains a JSP webshell. The web server accepts the file, stores it at a predictable location under the uploadfile directory, and then executes it. This delivers remote code execution to the server and corresponds to CWE-434.
Affected Systems
The flaw is present in Guangzhou Red Sea Cloud Computing Co., Ltd.’s Red Sea Cloud eHR product. No specific version numbers are listed for affected releases.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical severity, and the EPSS value of < 1% suggests a historically low but non‑zero exploitation probability. However, proof of exploitation was observed in November 2024, showing that attackers can successfully exercise the flaw with ordinary web traffic. The vulnerability is not listed in the CISA KEV catalog, but the evidence of exploitation means that any organization running the affected product is at high risk. The attack path requires only the ability to reach the PtFjk.mob endpoint and craft a multipart POST; no authentication or privileged access is needed.
OpenCVE Enrichment