Soar Cloud HRD Human Resource Management System External Control of File Name or Path Vulnerability

Vulnerability

A vulnerability allowing external control of file names or paths has been identified in the download file function of Soar Cloud HRD Human Resource Management System, through version 7.3.2025.0408. This vulnerability allows remote attackers to obtain partial files by specifying arbitrary file paths.

Impact

Exploitation of this vulnerability could lead to unauthorized access to partial files on the server.

Added: Jun 6, 2025, 10:21 AM
Updated: Jun 6, 2025, 10:21 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.3
exploitability
7.4
remediation
0.0
relevance
0.1
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.