在 lenve vhr 1.0-SNAPSHOT 中发现了一个安全弱点。该漏洞影响“头像上传”组件中 /hr/userface 文件里的 FastDFSUtils.upload 函数。由于对参数 File 的处理不当,导致文件上传功能未加限制(unrestricted file upload)。该漏洞可被远程利用,且利用方式(exploit)已公开,可能被用于发起攻击。厂商已提前得知此漏洞披露信息,但始终未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90498 | 7.3 HIGH | lenve vhr vhr.sql default credentials |
| CVE-2026-90490 | 6.3 MEDIUM | lenve vhr MailReceiver deserialization |
| CVE-2026-90501 | 6.3 MEDIUM | lenve vhr HrMapper.xml HrInfoController.updateHr privileges management |
| CVE-2026-90499 | 5.4 MEDIUM | lenve vhr Password Update pass HrInfoController.updatePass improper authorization |
No comments yet