The PHP executable in Projoom NovaSFH plugin version 3.0.3 which is responsible for handling file upload functionality allows arbitrary files to be uploaded to any directory specified by the attackers as the file upload function does not does not verify file type or origin when processing the request.
1fb1ff77a2d570b27d8c0f997848425e0da6209fa9f402349bebb84194b11cd2