The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2021-02-17T13:30:19.537050Z

Updated: 2024-09-17T04:04:36.098Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2021-22853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-02-17T14:15:19.153

Modified: 2023-11-07T03:30:26.120

Link: CVE-2021-22853

cve-icon Redhat

No data.