CVE-2026-90500 | lenve vhr 1.0-SNAPSHOT Avatar Upload /hr/userface FastDFSUtils.upload File unrestricted upload
A vulnerability classified as critical has been found in lenve vhr 1.0-SNAPSHOT. This vulnerability affects the function FastDFSUtils.upload of the file /hr/userface of the component Avatar Upload. This manipulation of the argument File causes unrestricted upload.
This vulnerability is tracked as CVE-2026-90500. The attack is possible to be carried out remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.