CVE-2025-48784
- EPSS 0.08%
- Veröffentlicht 06.06.2025 09:28:39
- Zuletzt bearbeitet 04.02.2026 14:32:38
A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to modify system settings without prior authorization.
CVE-2025-48783
- EPSS 0.08%
- Veröffentlicht 06.06.2025 09:27:01
- Zuletzt bearbeitet 04.02.2026 14:36:46
An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to delete partial files by specifying arbitrary file paths.
CVE-2025-48782
- EPSS 0.24%
- Veröffentlicht 06.06.2025 09:24:17
- Zuletzt bearbeitet 04.02.2026 14:38:52
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious...
CVE-2025-48781
- EPSS 0.09%
- Veröffentlicht 06.06.2025 09:21:58
- Zuletzt bearbeitet 04.02.2026 15:00:10
An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to obtain partial files by specifying arbitrary file paths.
CVE-2025-48780
- EPSS 0.55%
- Veröffentlicht 06.06.2025 09:19:04
- Zuletzt bearbeitet 04.02.2026 15:02:46
A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a crafted serialized obj...
CVE-2025-5192
- EPSS 0.19%
- Veröffentlicht 06.06.2025 09:15:17
- Zuletzt bearbeitet 04.02.2026 14:28:22
A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.
CVE-2024-5995
- EPSS 0.23%
- Veröffentlicht 14.06.2024 08:15:43
- Zuletzt bearbeitet 21.11.2024 09:48:43
The notification emails sent by Soar Cloud HR Portal contain a link with a embedded session. The expiration of the session is not properly configured, remaining valid for more than 7 days and can be reused.
CVE-2023-34357
- EPSS 0.03%
- Veröffentlicht 07.09.2023 03:15:08
- Zuletzt bearbeitet 21.11.2024 08:07:05
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through e-mail, and the link will remain valid after the password has been reset and after the expected expiration date. An att...