Junglewise Threat Intelligence

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

Severity: low · CVSS 3.1 · Published 2026-07-10

Technologies: notrinos/notrinos-erp (Packagist). Vendors: Packagist.

Executive brief

NotrinosERP: Authenticated arbitrary file upload leads to remote code execution via HRM employee "Documents" (doc_file)

Affected products

  • Packagist notrinos/notrinos-erp

Related threats