Impact
The vhr application does not validate whether the requester is authorized to modify a given HR profile when processing a PUT /hr/info request. An authenticated user can provide any profile ID in the request body and alter the target’s name, address, or even disable the account. This flaw allows attackers to tamper with other users’ personal data or cripple service availability by disabling administrator accounts, thereby violating confidentiality, integrity, and availability of HR information.
Affected Systems
The vulnerability affects the vhr product from vendor lenve across all released versions, as no specific version identifiers were listed. Any deployment of this application that exposes the PUT /hr/info endpoint to authenticated users is vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 7.2, indicating a high severity. External Proactive Systems Score (EPSS) is not available, so exact exploit probability is unknown, and the vulnerability has not been listed in the CISA KEV catalog. Because authentication is required to exploit the issue, the likely attack vector is an authenticated user with application access, possibly internal employees or attackers who compromised credentials. Once authenticated, an attacker can overwrite arbitrary HR profiles, leading to data corruption and potential denial of service if administrative accounts are disabled.
OpenCVE Enrichment