Junglewise Threat Intelligence

CVE-2024-14037: Redsea Cloud eHR arbitrary file upload in PtFjk.mob servlet

CVE-2024-14037 · Severity: critical · CVSS 9.8 · Published 2026-07-02

Executive brief

Redsea Cloud eHR, a human resources management platform, contains a critical security flaw that allows unauthorized individuals to upload and execute malicious files on the server. By exploiting this vulnerability, an attacker can gain full control over the system without needing a username or password. This could lead to the theft of sensitive employee data, complete service disruption, or the use of the server for further attacks against the organization.

Technical details

An arbitrary file upload vulnerability exists in the PtFjk.mob servlet endpoint of Redsea Cloud eHR due to a lack of file extension and MIME type validation. Unauthenticated attackers can exploit this by sending a multipart POST request containing a JSP webshell, using a spoofed 'image/jpeg' Content-Type to bypass basic security checks. The uploaded file is stored in a predictable directory structure under '/uploadfile/' and can be directly accessed and executed by the web server. This leads to full remote code execution (RCE) with the privileges of the web service user. Exploitation in the wild was reported as early as November 2024.

Affected products

  • Guangzhou Red Sea Cloud Computing Co., Ltd. Redsea Cloud eHR All versions (Cloud-based)

Timeline

  • 2024-05-14: disclosed: Initial public disclosure of the vulnerability and POC
  • 2024-11-03: exploited: First evidence of exploitation observed by Shadowserver Foundation
  • 2026-07-02: advisory: NVD and VulnCheck advisory published

References