Wukong_HRM(在提交 186115e 版本中)存在一个缺失的授权漏洞。原因是 EmployeeAspect 将所有调用者赋予了 HR 管理员角色,并且 EmployeeUtil 中的数据范围检查返回所有员工的数据。任何经过身份验证的低权限员工都可以读取工资单、薪资记录、银行卡和个人信息,编辑银行卡,并删除整个公司的员工、部门和合同信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WuKongOpenSource | Wukong_HRM | 0 ~ 186115e1a5a0b827ad9596ff8c2f3a876fb0cc55 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-108707 | 9.8 CRITICAL | Wukong_HRM through commit 186115e Authentication Bypass via ParamAspect |
| CVE-2026-108689 | 5.4 MEDIUM | Wukong AICRM through 20260610 Authorization Bypass via User-Controlled Session ID in POST |
No comments yet