Bilin HUMANIST Digital Human Resources是土耳其Bilin公司的一款人力资源管理软件。 Bilin HUMANIST Digital Human Resources 26.0至26.1之前版本存在输入验证错误漏洞,该漏洞源于URL重定向到不受信任的站点(开放重定向),可能导致网络钓鱼攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | 26.0< 26.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Bilin Software and Informatics Consultancy Inc. | HUMANIST Digital Human Resources | 26.0 ~ 26.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15721 | 9.8 CRITICAL | Query Console SQL Injection Leading to Sensitive Data Disclosure in Bilin Software's HUMAN |
| CVE-2026-14175 | 9.8 CRITICAL | Unrestricted File Upload in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14804 | 9.1 CRITICAL | Hardcoded Cryptographic Key in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14838 | 7.4 HIGH | Session Token Exposure in URL Leading to Account Takeover in Bilin Software's HUMANIST Dig |
| CVE-2026-14194 | 6.5 MEDIUM | Path Traversal Allows Arbitrary File Download in Bilin Software's HUMANIST Digital Human R |
| CVE-2026-14465 | 6.5 MEDIUM | Session Fixation in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14192 | 5.4 MEDIUM | Stored XSS in Bilin Software's HUMANIST Digital Human Resources |
| CVE-2026-14202 | 5.3 MEDIUM | Username Enumeration via Differential Login Responses in Bilin Software's HUMANIST Digital |
No comments yet