Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
vhr Missing Authorization in PUT /hr/pass Allows Cross-Account Password Change
Vulnerability Description
vhr through commit 03abbd3 fails to verify that the account ID in PUT /hr/pass requests belongs to the authenticated caller. Authenticated attackers can change arbitrary account passwords by supplying a target account ID and that account's current password in the request body.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
lenve vhr 授权问题漏洞
Vulnerability Description
lenve vhr是lenve个人开发者的一款具备员工管理、考勤与组织架构功能的企业人事管理系统。 lenve vhr 03abbd3及之前版本存在授权问题漏洞,该漏洞源于未验证PUT /hr/pass请求中的账户ID是否属于已认证调用者,可能导致已认证攻击者更改任意账户密码。
CVSS Information
N/A
Vulnerability Type
N/A