在 lenve vhr 1.0-SNAPSHOT 中发现了一个安全漏洞。该漏洞影响了位于 /hr/pass 文件中 HrInfoController.updatePass 函数,组件“密码更新处理器”(Password Update Handler)中参数 hrid 的处理存在不当授权问题。该攻击可以远程执行。利用代码已公开,并可能被用于发起攻击。早在该漏洞披露前,已联系过供应商,但供应商未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90498 | 7.3 HIGH | lenve vhr vhr.sql default credentials |
| CVE-2026-90490 | 6.3 MEDIUM | lenve vhr MailReceiver deserialization |
| CVE-2026-90500 | 6.3 MEDIUM | lenve vhr Avatar Upload userface FastDFSUtils.upload unrestricted upload |
| CVE-2026-90501 | 6.3 MEDIUM | lenve vhr HrMapper.xml HrInfoController.updateHr privileges management |
No comments yet