Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
vhr Missing Authorization in PUT /hr/info Allows Arbitrary Profile Overwrite
Vulnerability Description
vhr fails to validate user authorization in the PUT /hr/info endpoint, allowing authenticated users to modify arbitrary HR profiles by supplying any profile ID in the request body. Attackers can overwrite other users' names, addresses, and disable accounts including administrators to cause denial of service.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Vulnerability Type
通过用户控制密钥绕过授权机制
Vulnerability Title
lenve vhr 授权问题漏洞
Vulnerability Description
lenve vhr是lenve个人开发者的一款具备员工管理、考勤与组织架构功能的企业人事管理系统。 lenve vhr存在授权问题漏洞,该漏洞源于在PUT /hr/info端点未正确验证用户授权,允许已认证用户通过提供任意profile ID修改任意HR资料,攻击者可覆盖其他用户的姓名、地址并禁用包括管理员在内的账户,导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A