Impact
The vulnerability is an insecure direct object reference that allows an authenticated attacker to send a PUT request to the employee update endpoint with any employee identifier and change the controlled fields, enabling account takeover, enumeration of employee records, and retrieval of confidential personal data. The direct exposure of an employee identifier without ownership validation creates a critical privilege escalation bug.
Affected Systems
SIMAC MyPHR version 1.1 is affected. No additional product versions are listed. Administrators should verify that any deployments of the 1.1 build are reviewed for this issue.
Risk and Exploitability
The CVSS score of 8.7 indicates a high impact severity. The EPSS score of less than 1% suggests that, as of current data, the exploitation probability is low. It is not listed in CISA KEV. Attackers need an authenticated session to reach the endpoint; once authenticated, the missing server‑side ownership check enables the takeover. Therefore, while the exploitation likelihood is modest, the potential impact is substantial if the vulnerability is exploited.
OpenCVE Enrichment