PT-2019-13874 · Humanica · Humatrix

Nuttakorn Dhiraprayudti

·

Publicado

2019-08-12

·

Atualizado

2021-07-21

·

CVE-2019-14932

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Humanica Humatrix versions 1.0.0.681 and 1.0.0.203
Description The issue allows remote attackers to access sensitive data, including personal information, by modifying the selApp variable to access the "personalData/resumeDetail.cfm" endpoint. This affects the Recruitment module, potentially exposing all candidates' information on the website.
Recommendations For version 1.0.0.681, restrict access to the "personalData/resumeDetail.cfm" endpoint to minimize the risk of exploitation. For version 1.0.0.203, avoid using the modified selApp variable in the Recruitment module until the issue is resolved. As a temporary workaround, consider disabling access to the Recruitment module until a fix is available.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-14932

Produtos afetados

Humatrix