Impact
A flaw in Lenve VHR version 1.0‑Snapshot allows an attacker to manipulate the hrid argument in the HrInfoController.updatePass function, enabling them to change the password of any user without proper authorization. This results in unauthorized credential modification, allowing an attacker to assume the identity of any user, potentially leading to broader account compromise and data theft. The weakness is an improper authorization flaw, classified as CWE-266 and CWE-285.
Affected Systems
The vulnerability affects the Lenve VHR version 1.0‑Snapshot Password Update Handler component. No other versions were listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of <1% indicates a very low likelihood of exploitation, but the vulnerability is publicly available and can be executed remotely. The vulnerability is not listed in CISA’s KEV catalog. The attack can be carried out remotely by manipulating an HTTP request to /hr/pass, and the exploit has already been released to the public.
OpenCVE Enrichment