VulnerabilityModified
CVE-2021-22853
While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.
MEDIUM 5.4EPSS 1.04%
Does this matter?
Lower severity and a low EPSS score (1.04%). Track it; it rarely justifies an emergency change on its own.
Description
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive data via a specific data packet, such as user’s login information, further causing the login function not to work.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- hr portal project/hr portal
- Source
- twcert@cert.org.tw
References
- https://www.chtsecurity.com/news/d334641f-2b28-4eab-a5ed-c6ec6740557eThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4403-8eb68-1.htmlThird Party Advisory
- https://www.chtsecurity.com/news/d334641f-2b28-4eab-a5ed-c6ec6740557eThird Party Advisory
- https://www.twcert.org.tw/tw/cp-132-4403-8eb68-1.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.