Wukong_HRM 在提交 186115e 中存在一个由 ParamAspect 引发的身份验证绕过漏洞,攻击者可以通过省略 AUTH-TOKEN 头信息,以未授权的方式访问 HRM 的所有 API 端点。利用该漏洞,攻击者可获得 HR 管理员权限,从而读取工资单、薪资历史及员工个人数据,下载附件,并修改或删除公司范围内的 HR 记录。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WuKongOpenSource | Wukong_HRM | 0 ~ 186115e1a5a0b827ad9596ff8c2f3a876fb0cc55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108708 | 8.8 HIGH | Wukong_HRM through commit 186115e Missing Authorization via EmployeeAspect and EmployeeUti |
| CVE-2026-108689 | 5.4 MEDIUM | Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST |
No comments yet