PT-2026-3924 · Hamastar Technology · Meetinghub

Alan Chung

·

Published

2026-01-22

·

Updated

2026-02-17

·

CVE-2026-1331

CVSS v3.1
9.8
VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MeetingHub (affected versions not specified)
Description MeetingHub, developed by HAMASTAR Technology, has an arbitrary file upload issue. This allows unauthenticated remote attackers to upload and execute web shell backdoors, leading to arbitrary code execution on the server. The issue allows for the upload of files, such as
test.php
, via a POST request to the
/upload
API endpoint. Successful exploitation enables remote code execution (RCE) without authentication.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-1331

Affected Products

Meetinghub