Impact
The vulnerability arises when session tokens are embedded in the query string of a GET request. This allows attackers to capture or guess the token and hijack an authenticated session. The result is a full account takeover, giving the attacker confidentiality, integrity, and availability control over the victim’s data within HUMANIST Digital Human Resources. The weakness is identified as CWE‑598, a token exposure issue.
Affected Systems
Bilin Software and Informatics Consultancy Inc. provide HUMANIST Digital Human Resources. The product is vulnerable in version 26.0 and earlier; versions 26.1 or later contain the fix.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity. EPSS information is not available, and the vulnerability is not listed in CISA KEV. Attackers can exploit the flaw by sending a crafted URL or by sniffing traffic that contains the session token, before the token expires. Because the code uses a GET method, the token is exposed in logs, browser history, and referrers, making the exploitation likely if the network is intercepted or if the URL is inadvertently shared.
OpenCVE Enrichment