Exploit Title: NEProfile - Remote Code Execution Date: 5/13/2020 Vendor Homepage: https://seczetta.com Software Link: https://seczetta.com/product/ne-profile Version: 3.3.11 Tested on: 3.3.11 Exploit Author: Josh Sheppard Exploit Contact: ghost () a t undervurse dot_com Exploit Technique: Remote CVE ID: CVE-2020-12854 1. Description A remote code execution vulnerability was identified in SecZetta's NEProfile product. Authenticated remote adversaries can invoke code execution upon uploading a carefully crafted jpg as part of the profile avatar. The issue affects version 3.3.11 and has not been tested on other versions of the product. 2. Disclosure Timeline 5/4/20 - Discovery and Exploitation 5/12/20 - Vendor Notified 6/18/20 - Patch / Hotfix Created 3. Mitigation Apply hotfix provided by vendor