Impact
The flaw is an improper access control that allows standard employees to change the approval status of documents they themselves have uploaded. By bypassing a server‑side authorization check, an attacker with only employee permissions can alter application state that should be restricted to administrators. This violation of access control (CWE‑284) undermines the integrity of HR processes such as credential verification and material acceptance.
Affected Systems
The vulnerability affects the Horilla Human Resource Management System, version 1.4.0. The flaw was corrected in version 1.5.0, so systems running the 1.4.0 release are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate impact. The EPSS score of less than 1 % suggests a very low probability of exploitation, and the CVE is not listed in CISA’s KEV catalog. The attack requires an authenticated employee who can access the approval endpoint, so the most likely vector is a legitimate user exploiting the missing server‑side check.
OpenCVE Enrichment