CVE-2025-48783
BaseFortify
Publication date: 2025-06-06
Last updated on: 2026-02-04
Assigner: ZUSO Advanced Research Team (ZUSO ART)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| scshr | hr_portal | to 7.3.2025.0408 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-73 | The product allows user input to control or influence paths or file names that are used in filesystem operations. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an external control of file name or path issue in the delete file function of the Soar Cloud HRD Human Resource Management System up to version 7.3.2025.0408. It allows remote attackers to delete partial files by specifying arbitrary file paths, meaning they can potentially delete files they should not have access to by manipulating the file path input.
How can this vulnerability impact me? :
This vulnerability can allow remote attackers to delete important files on the system running the Soar Cloud HRD Human Resource Management System, potentially leading to data loss, disruption of service, or damage to the integrity of the system's data.