MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.
The attacker sends an HTTP request containing a malicious file (e.g., web shell) to the vulnerable MeetingHub application endpoint without needing to have an account or session. The application does not properly validate the type or content of the uploaded file, resulting in the file being saved to a location accessible by the web server. The attacker then invokes the uploaded file through a browser or HTTP request, resulting in arbitrary code execution on the server side.
Attacker gains the ability to execute arbitrary code on the server (RCE) with the privileges of the web server process, which may lead to full system compromise, data theft, installation of additional malware, or further lateral movement in the network.
Patches available from the vendor should be applied in accordance with references published by TWCERT at https://www.twcert.org.tw/en/cp-139-10651-ff09c-2.html and https://www.twcert.org.tw/tw/cp-132-10650-a5ee9-1.html. Until the patch is installed, it is recommended to restrict access to file upload functionality at the firewall or reverse proxy level and monitor server directories for new, unauthorized executable files.
Hamastar MeetingHub Paperless Meetings product — versions indicated in vendor references (TWCERT)
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XHamastar Meetinghub Paperless Meetings
APPHamastar< 2025-12-10
Related vulnerabilities
Nieograniczony upload plików w Hamastar MeetingHub — zdalne wykonanie poleceń
Hamastar MeetingHub: hasła przechowywane w postaci jawnej w plikach XML
MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated...
MeetingHub opracowany przez HAMASTAR Technology posiada lukę Missing Authentication, umożliwiającą nieuwierzyt...