CyberRota Analysis
AI-GeneratedA vulnerability in the Avatar Upload component of lenve vhr 1.0-SNAPSHOT allows for unrestricted file uploads through the FastDFSUtils.upload function, posing a risk of remote exploitation. This weakness can lead to unauthorized file uploads, potentially enabling attackers to execute malicious code or compromise the system. Organizations using this software should prioritize remediation to mitigate the risk of exploitation, especially if they handle sensitive data or are exposed to the internet.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A weakness has been identified in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.