← Back to CVE List

CVE-2018-18382

Published: 2018-10-16T07:29Z
Last Modified: 2024-11-21T03:55Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Advanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed through an "Update Profile" "Change Picture" (aka user/edit-profile) action. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt