RULE(RULE ID:338550)

Rule General Information
Release Date: 2024-11-19
Rule Name: Hjsoft eHR uploadLogo Arbitrary File Upload Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Hjsoft eHR Human Resources Information Management System is a software that comprehensively covers all modules of human resource management. It aims to help enterprises and institutions build high-performance organizations, promote healthy organizational growth, and enhance organizational soft power. There is an arbitrary file upload vulnerability in the system's uploadLogo, which can be used to execute code arbitrarily on the server, write back doors, obtain server permissions, and then control the entire web server.
Impact: Attackers can upload viruses, Trojans, WebShell, other malicious scripts or pictures containing scripts to the server, and attackers can use these files for subsequent attacks.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.