Impact
The flaw is in the HrInfoController.updateHr method of lenve vhr 1.0‑SNAPSHOT. By tampering with the Password argument in a request to the updateHr endpoint, an attacker can bypass existing privilege checks because the application does not verify that the caller is authorized to effect the to elevate their privileges beyond the intended level, and the vulnerability is classified as CWE‑266 and CWE‑269.
Affected Systems
Only the 1.0‑SNAPSHOT release of lenve vhr is affected. No other versions or variants have been reported as impacted. The flaw resides in the HrMapper.xml configuration that maps the updateHr endpoint.
Risk and Exploitability
The CVSS score of 5.3 places the incident in the medium severity tier. Because the attack vector is remote, an adversary can remotely exploit the flaw by sending a crafted request to the updateHr endpoint. The EPSS score is < 1%, indicating a very low probability of exploitation, and the vulnerability is not yet cataloged in CISA KEV. While there is no confirmed exploitation, the potential for privilege escalation combined with a remote access path means that the issue could provide attackers a foothold if other network or application exposure exists.
OpenCVE Enrichment