Impact
The vulnerability is an improper limitation of a pathname to a restricted directory, known as path traversal. It allows an attacker to construct file paths that escape the intended directory and retrieve arbitrary files from the server. The impact is the loss of confidentiality through unauthorized file download, potentially exposing sensitive data contained on the host.
Affected Systems
Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources is affected. All installations with version 26.0 or earlier contain the flaw; the issue is fixed in version 26.1 and later.
Risk and Exploitability
The CVSS base score of 6.5 indicates a moderate severity vulnerability. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is likely remote, via a web request to the application. An attacker would need to manipulate a file path in a request to the vulnerable component; authentication requirements are not specified in the data, so the risk remains uncertain but potentially high given the ability to download any file.
OpenCVE Enrichment