Impact
The vulnerability is caused by a missing authorization check in the expire_allocation method of Frappe HR. An authenticated user can issue a POST request that targets any employee’s leave allocation record and sets the allocated leaves to zero, effectively erasing that employee’s remaining leave balance. This flaw permits an attacker to tamper with employee leave data, undermining the integrity of personnel records and potentially violating compliance requirements.
Affected Systems
All Frappe HR (hrms) releases before 16.11.0—including every 14.x and 15.x version up to 15.64.3—contain the bug. The affected code is in the hrms module’s leave_ledger_entry.py file. The issue was fixed in release v16.11.0.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium level of risk, and the vulnerability is not listed in the CISA KEV catalog. EPSS information is not available, so exploitation probability cannot be quantified. Attackers only need to be authenticated and do not require HR roles, giving a broad attack surface and a straightforward path to abuse the flaw.
OpenCVE Enrichment