Impact
The vulnerability is an insufficient session expiration flaw that permits session IDs to be reused, enabling session replay attacks. This flaw, classified as CWE‑613, allows an attacker to hijack or impersonate a user by capturing and reusing a valid session ID, effectively bypassing authentication mechanisms. The impact includes unauthorized access to protected resources and potential data compromise on the affected system.
Affected Systems
The flaw affects Bilin Software and Informatics Consultancy Inc.'s HUMANIST Digital Human Resources application in versions prior to 26.1, specifically 26.0 and earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity. EPSS data is not available, and the vulnerability is not listed in CISA's KEV catalog, suggesting limited publicly known exploitation. The likely attack vector involves an attacker capturing a session ID through network sniffing, phishing, or other means and then reusing that ID to gain unauthorized access, potentially from within the same session context. The risk is moderate, but the lack of immediate exploitation evidence means that a vigilant monitoring stance is advisable.
OpenCVE Enrichment