CVE-2026-1331 PUBLISHED

AMASTAR Technology|MeetingHub - Arbitrary File Upload

Assigner: twcert
Reserved: 22.01.2026 Published: 22.01.2026 Updated: 22.01.2026

MeetingHub developed by HAMASTAR Technology has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor AMASTAR Technology
Product MeetingHub
Versions Default: unaffected
  • Version 0 is affected

Solutions

Install the patch with version 20251210 or later.

References

Problem Types

  • CWE-434 Unrestricted Upload of File with Dangerous Type CWE

Impacts

  • CAPEC-650 Upload a Web Shell to a Web Server