Impact
The vulnerability allows an attacker to upload arbitrary files, including web shells, to the server without any restriction on the file type. This flaw enables remote code execution, giving an attacker full control of the application or underlying server, potentially compromising confidentiality, integrity, and availability of the entire system.
Affected Systems
Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources is affected. The issue applies to all versions prior to 26.1, including the 26.0 release.
Risk and Exploitability
With a CVSS score of 9.8 the vulnerability is considered critical. The EPSS score is not provided, so the current exploitation probability cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is through the web upload interface, where the attacker can directly upload a malicious file. The absence of server‑side validation allows the uploaded file to be executed by the web server, leading to a breakdown of all security controls.
OpenCVE Enrichment