The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Hr_portal | Hr_portal_project | 7.3.2020.1013 (including) | 7.3.2020.1013 (including) |