Wolters Kluwer TeamMate AM 12.4 Update 1 mishandles attachment uploads, such that an authenticated user may download and execute malicious files.
https://www.wolterskluwer.com/en/solutions/teammate
https://excellium-services.com/cert-xlm-advisory/CVE-2021-44035