Bilin HUMANIST Digital Human Resources是土耳其Bilin公司的一款人力资源管理软件。 Bilin HUMANIST Digital Human Resources存在路径遍历漏洞,该漏洞源于对受限目录的路径名限制不当。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | 26.0< 26.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | 26.0 ~ 26.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15721 | 9.8 CRITICAL | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMAN |
| CVE-2026-14175 | 9.8 CRITICAL | Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14804 | 9.1 CRITICAL | Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14838 | 7.4 HIGH | Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Dig |
| CVE-2026-14465 | 6.5 MEDIUM | Session Fixation in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14192 | 5.4 MEDIUM | Stored XSS in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14219 | 5.4 MEDIUM | URL Redirection in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14202 | 5.3 MEDIUM | Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digital |
No comments yet