Impact
The vulnerability is an authentication bypass in ParamAspect that allows unauthenticated callers to invoke any HRM API endpoint by omitting the AUTH‑TOKEN header. Attackers gain administrator‑level access to sensitive personal data, salary information, and can modify or delete records, thereby compromising confidentiality, integrity, and potentially availability of HR data.
Affected Systems
Affected product is WuKongOpenSource’s Wukong_HRM, specifically versions that include commit 186115e. No explicit version range is provided; any release containing that commit is vulnerable.
Risk and Exploitability
With a CVSS score of 9.3, this flaw poses a critical risk. The EPSS score is not available and the vulnerability is not listed in CISA KEV, but the attack vector is likely remote via web API calls that omit the AUTH‑TOKEN header. The vulnerability can be exploited by any unauthenticated user to perform privileged operations, which makes it a high‑priority issue for organizations running this application.
OpenCVE Enrichment