Impact
The vulnerability in Wukong_HRM around commit 186115e allows any authenticated user, even those with low privileges, to assume the role of a full HR administrator due to a flaw in EmployeeAspect. The flaw causes EmployeeUtil to return all employees in a data‑scope check, permitting abuse of sensitive endpoints. As a result, a malicious actor can read private payslips, salary histories, bank card numbers, social security identifiers, modify bank card information, and delete employees, departments, or contracts across the entire organization. The consequence is a loss of confidentiality, integrity, and potential availability of crucial HR data.
Affected Systems
WuKongOpenSource’s Wukong_HRM application is affected. The break in authorizationability exists in the codebase at commit 186115e, which has been identified as the point where EmployeeAspect assigns the HR administrator role to all callers and EmployeeUtil data scopes become unconstrained. No specific version range is listed, but any build that includes or has not yet applied the changes from the commit is vulnerable.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity due to the broad scope and significant impact on proprietary HR data. Although EPSS is not available and the vulnerability is not listed in KEV, the exposure to an authenticated user lowers the required attack conditions compared to an unauthenticated exploit. An attacker must be authenticated to the web application, but any logged‑in employee can trigger the unauthorized actions, making exploitation straightforward once credentials are obtained. The vulnerability is likely to be present in versions that contain commit 186115e or any earlier releases that have not incorporated a patch that restores proper authorization checks.
OpenCVE Enrichment