CVE-2025-48784
BaseFortify
Publication date: 2025-06-06
Last updated on: 2026-02-04
Assigner: ZUSO Advanced Research Team (ZUSO ART)
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| scshr | hr_portal | to 7.3.2025.0408 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a missing authorization flaw in the Soar Cloud HRD Human Resource Management System up to version 7.3.2025.0408. It allows remote attackers to modify system settings without needing prior authorization, meaning unauthorized users can change configurations that should be protected.
How can this vulnerability impact me? :
The vulnerability can lead to unauthorized changes in system settings by remote attackers, potentially compromising the integrity and security of the HR management system. This could result in system misconfigurations, data manipulation, or further exploitation of the system.