Security: zelon88/HRConvert2
Security
No security policy detected
This project has not set up a SECURITY.md file yet.
Report a vulnerability-
Unauthenticated arbitrary file read via sanitizeSCAD() bypass in HRConvert2 v3.5.4GHSA-qcq3-837w-2c9c published
Aug 5, 2026 by zelon88High -
File deletion never removes the web-served copy (use-before-assign in deleteFiles)GHSA-cwc2-f9j8-x8m2 published
Aug 3, 2026 by zelon88Moderate -
Anonymous cross-session file disclosure via date+salt-predictable session hashes and web-served logsGHSA-qj74-5h4j-f368 published
Aug 3, 2026 by zelon88High -
Unauthenticated OS command injection (RCE) via sanitizeString() order-of-operations in convertCore.phpGHSA-wg57-wvw2-9cj8 published
Aug 3, 2026 by zelon88Critical -
Missing Sanitization enables Unauthenticated Remote Command ExecutionGHSA-f74g-4wj8-j35h published
May 4, 2026 by zelon88Critical
Learn more about advisories related to zelon88/HRConvert2 in the GitHub Advisory Database