HAMASTAR Technology MeetingHub Absolute Path Traversal Vulnerability Allowing Arbitrary File Read

Vulnerability

A vulnerability allowing arbitrary file read has been identified in MeetingHub, developed by HAMASTAR Technology. This issue arises from absolute path traversal, enabling unauthenticated remote attackers to download arbitrary system files. The vulnerability affects MeetingHub versions prior to the patch released on December 10, 2025.

Impact

Exploitation of this vulnerability allows for unauthorized access to sensitive system files, which could lead to further exploitation or information disclosure.

Remediation

Users are advised to update to version 20251210 or later.

Added: Jan 22, 2026, 9:19 AM
Updated: Jan 22, 2026, 9:19 AM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
3.3
exploitability
7.0
remediation
7.7
relevance
2.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.