In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Link | Tags |
---|---|
https://www.youtube.com/watch?v=gnSMrvV5e9w | third party advisory exploit |
https://blog.pocas.kr/posts/rce-KEA-Hotel-ERP/ | broken link |
https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#cve-2021-46113 | third party advisory exploit |