在 Omega Solution FBP Fulfillment by People 2025 中发现了一个安全漏洞。该漏洞影响 User Profile API 组件中 /user/ 文件下的一个未知功能。通过对参数 ID 的操纵,攻击者可以绕过授权机制。该漏洞可被远程利用。利用方法已公开披露,可能被实际使用。厂商已提前获知此披露,但至今未作任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Omega Solution | FBP Fulfillment by People | 2025 |
cpe:2.3:a:omega_solution:fbp_fulfillment_by_people:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-94151 | 5.3 MEDIUM | Omega Solution HRM OS Role Permission API permission missing authentication |
| CVE-2026-94149 | 4.3 MEDIUM | Omega Solution HRM OS Role Permission Retrieval Endpoint permission resource injection |
| CVE-2026-94150 | 2.4 LOW | Omega Solution HRM OS SVG File Upload view cross site scripting |
No comments yet