PT-2019-13874 · Humanica · Humatrix

Nuttakorn Dhiraprayudti

·

Published

2019-08-12

·

Updated

2021-07-21

·

CVE-2019-14932

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Humanica Humatrix versions 1.0.0.681 and 1.0.0.203
Description The issue allows remote attackers to access sensitive data, including personal information, by modifying the selApp variable to access the "personalData/resumeDetail.cfm" endpoint. This affects the Recruitment module, potentially exposing all candidates' information on the website.
Recommendations For version 1.0.0.681, restrict access to the "personalData/resumeDetail.cfm" endpoint to minimize the risk of exploitation. For version 1.0.0.203, avoid using the modified selApp variable in the Recruitment module until the issue is resolved. As a temporary workaround, consider disabling access to the Recruitment module until a fix is available.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-14932

Affected Products

Humatrix