Junglewise Threat Intelligence

NotrinosERP arbitrary file upload in HRM employee documents

Severity: high · CVSS 8.8 · Published 2026-07-10

Technologies: notrinos/notrinos-erp (Packagist). Vendors: Packagist.

Executive brief

NotrinosERP, an enterprise resource planning system, contains a flaw in its human resources module that allows authorized users to upload malicious files. An attacker with basic HR permissions can upload a script that executes on the server, potentially leading to a full system takeover, data theft, or service disruption. This occurs because the system does not properly check the type of files being uploaded in the employee documents section.

Technical details

An authenticated user with the 'SA_EMPLOYEE' permission can perform an unrestricted file upload in 'hrm/manage/employees.php' via the 'tab_documents()' function. The application fails to validate file extensions, MIME types, or content, and uses the client-provided filename verbatim when storing the file in a web-accessible directory ('company/0/documents/employees/'). By uploading a .php file, an attacker can achieve remote code execution (RCE). Additionally, the lack of filename sanitization may allow for path traversal (CWE-22) and stored cross-site scripting (CWE-79) in the 'View' link generation.

Affected products

  • Notrinos NotrinosERP <= 1.0.0

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References

Related threats