CRITICAL🇵🇱 Wersja polska

CVE-2026-1331

CVSS 9.3v4.0pub. 2026-01-22upd. 2026-02-17

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

🤖 AI Analysis
How it works

The attacker sends an HTTP request containing a malicious file (e.g., web shell) to the vulnerable MeetingHub application endpoint without needing to have an account or session. The application does not properly validate the type or content of the uploaded file, resulting in the file being saved to a location accessible by the web server. The attacker then invokes the uploaded file through a browser or HTTP request, resulting in arbitrary code execution on the server side.

Impact

Attacker gains the ability to execute arbitrary code on the server (RCE) with the privileges of the web server process, which may lead to full system compromise, data theft, installation of additional malware, or further lateral movement in the network.

Mitigation & patch

Patches available from the vendor should be applied in accordance with references published by TWCERT at https://www.twcert.org.tw/en/cp-139-10651-ff09c-2.html and https://www.twcert.org.tw/tw/cp-132-10650-a5ee9-1.html. Until the patch is installed, it is recommended to restrict access to file upload functionality at the firewall or reverse proxy level and monitor server directories for new, unauthorized executable files.

Who is affected

Hamastar MeetingHub Paperless Meetings product — versions indicated in vendor references (TWCERT)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Hamastar Meetinghub Paperless Meetings

    APP
    Hamastar
    < 2025-12-10
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2024-6117CRITICAL9.3PL ✓same product

Nieograniczony upload plików w Hamastar MeetingHub — zdalne wykonanie poleceń

CVE-2024-6118CRITICAL9.3PL ✓same product

Hamastar MeetingHub: hasła przechowywane w postaci jawnej w plikach XML

CVE-2026-1330HIGH8.7same product

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Read vulnerability, allowing unauthenticated...

CVE-2026-1332MEDIUM6.9same product

MeetingHub opracowany przez HAMASTAR Technology posiada lukę Missing Authentication, umożliwiającą nieuwierzyt...