PT-2026-41120 · Unknown · Hrconvert2

Khaelk138

·

Published

2026-05-14

·

Updated

2026-05-14

·

CVE-2026-44666

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions HRConvert2 versions prior to 3.3.8
Description The sanitizeString() function in convertCore.php fails to include backticks () and tabs (t) in its strip list. This allows user-supplied input to reach the shell exec()` function, enabling the shell to interpret these characters and execute commands embedded within filenames.
Recommendations Update to version 3.3.8. As a temporary workaround, restrict access to the sanitizeString() function in convertCore.php until the update is applied.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2026-44666

Affected Products

Hrconvert2