Impact
The vulnerability is an arbitrary file read exposed in the /api/model_report/file/download endpoint of Inspur Haiyue HCM Cloud. Unvalidated query parameters index and ext allow attackers to supply a traversal path such as /api/model_report/file/download?index=/&ext=../../../../etc/passwd to read any file on the server. This enables unauthenticated external users to access sensitive files, including system passwords, application database contents, and configuration data, thereby compromising confidentiality and potentially exposing credentials for further attacks.
Affected Systems
The affected product is Inspur Haiyue HCM Cloud. No specific version information is disclosed; the issue is present in all currently deployed instances that expose the vulnerable endpoint.
Risk and Exploitability
The CVSS score of 8.7 categorises the flaw as high severity, and the EPSS score is not available. It is not listed in the CISA KEV catalog. The flaw can be exploited by an unauthenticated attacker via a crafted HTTP request from the internet, making it a straightforward path‑traversal attack with no additional privileges required. Exploitation evidence was reported by Shadowserver Foundation on 2024-11-04.
OpenCVE Enrichment