CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-6117

CVSS 9.3v4.0pub. 2024-08-05upd. 2024-08-30

A Unrestricted upload of file with dangerous type vulnerability in meeting management function in Hamastar MeetingHub Paperless Meetings 2021 allows remote authenticated users to perform arbitrary system commands via a crafted ASP file.

🤖 AI Analysis
How it works

The meeting management function does not sufficiently verify the type of uploaded files, allowing an authenticated user to upload a crafted file with an ASP extension. After the file is placed on the server, the attacker can invoke it through a browser or HTTP request, resulting in execution of the contained code on the server side. In this way, it is possible to run arbitrary system commands in the context of the web server process.

Impact

An attacker with access to a user account can take control of the server by executing arbitrary system commands remotely (RCE), which may lead to data theft, backdoor installation, privilege escalation, or disruption of system availability.

Mitigation & patch

Security patches available from the vendor should be applied according to references. Additionally, it is recommended to restrict access to file upload functionality only to trusted users and implement server-side file type validation mechanisms (whitelist of allowed extensions and MIME types).

Who is affected

Hamastar MeetingHub Paperless Meetings 2021

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Hamastar Meetinghub Paperless Meetings

    APP
    Hamastar
    2021
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-1331CRITICAL9.3PL ✓same product

Arbitrary File Upload w Hamastar MeetingHub umożliwia RCE bez uwierzytelnienia

CVE-2024-6118CRITICAL9.3PL ✓same product

Hamastar MeetingHub: hasła przechowywane w postaci jawnej w plikach XML

CVE-2026-1330HIGH8.7same product

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated...

CVE-2026-1332MEDIUM6.9same product

MeetingHub opracowany przez HAMASTAR Technology posiada lukę Missing Authentication, umożliwiającą nieuwierzyt...