Impact
The vulnerability in IceHRM before v36.0.0 arises from missing ownership validation on seven REST sub‑resource endpoints, allowing any authenticated employee to retrieve the HR records of other personnel. The flaw effectively bypasses normal access controls, exposing sensitive personal data such as skills, education, certifications, languages, leave, attendance and status. This is a classic information disclosure weakness (CWE‑639). No mechanism for executing code or causing denial of service is described, so based on the description it is inferred that the impact is limited to confidentiality.
Affected Systems
The affected product is IceHRM, maintained by gamonoid. All releases prior to 36.0.0 are vulnerable. The bug manifests on the core employee REST sub‑resource endpoints for skill, education, certification, language, leave, attendance and status. The product is identified by the CPE icehrm:icehrm and may be deployed in internal HR environments.
Risk and Exploitability
The CVSS score of 7.1 indicates high severity. The EPSS score is <1%, indicating a very low probability of exploitation. The lack of a KEV listing does not mitigate the risk. Attack vector requires authentication within the system; external code execution or denial of service cannot be performed through this flaw. If an authenticated user has access to the system, the flaw permits them to read any employee’s confidential records, potentially leading to privacy violations or insider‑threat exploitation.
OpenCVE Enrichment