CVE-2019-15130
Severity CVSS v4.0:
Pending analysis
Type:
CWE-330
Use of Insufficiently Random Value
Publication date:
18/08/2019
Last modified:
21/07/2021
Description
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to upload any file type to a candidate's profile picture folder via a crafted recruitment_online/personalData/act_personaltab.cfm multiple-part POST request with a predictable WRC01_USERID parameter. Moreover, the attacker can upload executable content (e.g., asp or aspx) for executing OS commands on the server.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Base Score 2.0
10.00
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:humanica:humatrix_7:1.0.0.203:*:*:*:*:*:*:* | ||
| cpe:2.3:a:humanica:humatrix_7:1.0.0.681:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



