Description
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-13
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unrestricted File Upload
Action: Apply Workarounds
AI Analysis

Impact

The vulnerability resides in the FastDFSUtils.upload routine that handles the /hr/userface endpoint of the lenve vhr application. By manipulating the File argument, an attacker can upload arbitrary files to the server. Although the description does not confirm code execution, it is inferred that the ability to place malicious files on the filesystem could enable further attacks, such as hosting malware or attempting to execute payloads through additional vectors.

Affected Systems

This issue affects the lenve vhr product, specifically the Avatar Upload component in the 1.0-SNAPSHOT release. No other versions or products are mentioned as affected.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score is less than 1%, indicating a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. A public exploit is available, and the attack can be carried out remotely, making the risk significant. The flaw allows uploading of arbitrary files, which could be leveraged for subsequent attacks, though direct execution of uploaded content has not been confirmed. Based on the description, it is inferred that such files may be used for further exploitation.

Generated by OpenCVE AI on September 15, 2026 at 17:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • If no patch is available, limit the /hr/userface endpoint to authenticated users only, and enforce strict MIME type and file-extension validation on all uploads.
  • Configure the upload directory with restrictive permissions so that uploaded files cannot be executed or accessed directly from a web context.
  • Scan all uploaded files with antivirus or other scanning tools to detect malicious content before further processing.

Generated by OpenCVE AI on September 15, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Title lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload
First Time appeared Lenve
Lenve vhr
Weaknesses CWE-284
CWE-434
CPEs cpe:2.3:a:lenve:vhr:*:*:*:*:*:*:*:*
Vendors & Products Lenve
Lenve vhr
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-14T18:05:18.660Z

Reserved: 2026-09-12T08:24:09.879Z

Link: CVE-2026-90500

cve-icon Vulnrichment

Updated: 2026-09-14T18:05:14.031Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T08:16:25.980

Modified: 2026-09-14T20:56:48.220

Link: CVE-2026-90500

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-434

    Unrestricted Upload of File with Dangerous Type