In MartDevelopers KEA-Hotel-ERP open source as of 12-31-2021, a remote code execution vulnerability can be exploited by uploading PHP files using the file upload vulnerability in this service.
https://www.youtube.com/watch?v=gnSMrvV5e9w
https://gist.github.com/P0cas/5aa55f62781364a750ac4a4d47f319fa#cve-2021-46113