CyberRota Analysis
AI-GeneratedA vulnerability exists in the HrInfoController.updateHr function of the lenve vhr 1.0-SNAPSHOT application, allowing remote attackers to manipulate the Password argument, resulting in improper privilege management. This could lead to unauthorized access and potential escalation of privileges within the application. Organizations using this software should prioritize remediation efforts to mitigate the risk of exploitation, especially given the lack of vendor response to the disclosure.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
A security vulnerability has been detected in lenve vhr 1.0-SNAPSHOT. This issue affects the function HrInfoController.updateHr of the file HrMapper.xml. Such manipulation of the argument Password leads to improper privilege management. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.