Lucene search

K
cvelistMitreCVELIST:CVE-2019-15130
HistoryAug 18, 2019 - 4:23 p.m.

CVE-2019-15130

2019-08-1816:23:04
mitre
www.cve.org

9.5 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.9%

The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate’s profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the attacker can upload executable content (e.g., asp or aspx) for executing OS commands on the server.

9.5 High

AI Score

Confidence

High

0.006 Low

EPSS

Percentile

78.9%

Related for CVELIST:CVE-2019-15130