A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://zuso.ai/advisory/za-2025-04 |
|
History
Wed, 04 Feb 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Scshr
Scshr hr Portal |
|
| CPEs | cpe:2.3:a:scshr:hr_portal:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Scshr
Scshr hr Portal |
|
| Metrics |
cvssV3_1
|
Fri, 06 Jun 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Jun 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions. | |
| Title | Soar Cloud HRD Human Resource Management System - Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: ZUSO ART
Published:
Updated: 2025-06-06T13:59:48.427Z
Reserved: 2025-05-26T06:22:57.842Z
Link: CVE-2025-5192
Updated: 2025-06-06T13:59:36.762Z
Status : Analyzed
Published: 2025-06-06T10:15:24.630
Modified: 2026-02-04T14:28:22.197
Link: CVE-2025-5192
No data.
OpenCVE Enrichment
No data.