Rule Name:hr-soft EHR Arbitrary File Uplaod Vulnerability
Severity:high
CVE ID:
Descripiton:
The hr-soft EHR system is widely used by large and medium-sized enterprises to manage human resources. The system fully covers human resources management needs. The hr-soft EHR has an arbitrary file upload vulnerability, which allows attackers to upload malicious files through the kqFile.mob endpoint and ultimately control the server. This rule supports to defend the A6: Vulnerabe and Outdated Components of OWASP Top 10 - 2021. Other reference:None