A File Upload vulnerability exists in AvantFAX 3.3.7. An authenticated user can bypass PHP file type validation in FileUpload.php by uploading a specially crafted PHP file.
https://github.com/superkojiman/vulnerabilities/blob/master/AvantFAX-3.3.7/README.md