Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The Recruitment module in Humanica Humatrix 7 1.0.0.203 and 1.0.0.681 allows an unauthenticated attacker to access all candidates' files in the photo folder on the website by specifying a "user id" parameter and file name, such as in a recruitment_online/upload/user/[user_id]/photo/[file_name] URI.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Humanica Humatrix 7 Recruitment模块信息泄露漏洞
Vulnerability Description
Humanica Humatrix 7是一套人力资源管理解决方案。Recruitment是其中的一个招聘模块。 Humanica Humatrix 7 1.0.0.203版本和1.0.0.681版本中的Recruitment模块存在安全漏洞。攻击者可利用该漏洞访问网站上相片文件夹中的申请人文件。
CVSS Information
N/A
Vulnerability Type
N/A