A vulnerability marked as critical has been reported in 2-Plan Plan Team 1.0.4. Affected by this vulnerability is an unknown functionality of the file managefile.php. Performing a manipulation of the argument userfile1 results in unrestricted upload.
This vulnerability is reported as CVE-2018-25162. The attack is possible to be carried out remotely. Moreover, an exploit is present.