CyberRota Analysis
AI-GeneratedHUMANIST Digital Human Resources versions prior to 26.1 are vulnerable to an unrestricted file upload flaw, allowing attackers to upload malicious web shells to the server. This critical vulnerability (CVSS 9.8) can lead to full server compromise, enabling unauthorized access and potential data breaches. Organizations using affected versions should prioritize immediate remediation to mitigate the risk of exploitation.
Original NVD Description
Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Upload a Web Shell to a Web Server. This issue affects HUMANIST Digital Human Resources: from 26.0 before 26.1.