HR Portal Project
HR Portal Project HR Portal: vulnerabilities and CVEs
HR Portal Project HR Portal has 3 published vulnerabilities, 0 of them in the last 12 months. 1 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical1
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2021-22855 | Critical (9.8) | 2.0% | — | Feb 17, 2021 | The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands. |
| CVE-2021-22854 | High (7.5) | 1.6% | — | Feb 17, 2021 | The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege. |
| CVE-2021-22853 | Medium (5.4) | 1.0% | — | Feb 17, 2021 | The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the… |