IceHRM 在 36.0.0 之前的版本中,对七个 REST 子资源端点未能正确验证员工数据的所有权,使得已认证的能够读取任意同事的人力资源记录。攻击者可以在技能、教育、资质、语言、休假、考勤和状态等端点中替换任意的员工ID,从而访问敏感的人员数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet