HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its strip list. User input then reaches shell_exec(), where the shell interprets these characters and commands within filenames execute. This vulnerability is fixed in 3.3.8.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 May 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Zelon88
Zelon88 hrconvert2 |
|
| Vendors & Products |
Zelon88
Zelon88 hrconvert2 |
Thu, 14 May 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | HRConvert2 is a self-hosted, drag-and-drop & nosql file conversion server & share tool. Prior to 3.3.8, the sanitizeString() function in convertCore.php is missing backtick (`) and tab (\t) from its strip list. User input then reaches shell_exec(), where the shell interprets these characters and commands within filenames execute. This vulnerability is fixed in 3.3.8. | |
| Title | HRConvert2: Missing Sanitization enables Unauthenticated Remote Command Execution | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-14T20:32:43.490Z
Reserved: 2026-05-07T16:20:08.659Z
Link: CVE-2026-44666
No data.
Status : Received
Published: 2026-05-14T21:16:47.370
Modified: 2026-05-14T21:16:47.370
Link: CVE-2026-44666
No data.
OpenCVE Enrichment
Updated: 2026-05-15T11:21:04Z
Weaknesses