PT-2026-85041 · Vhr · Vhr
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
vhr versions prior to commit 03abbd3
Description
An authorization failure occurs when the system does not verify if the account ID provided in a request belongs to the authenticated user. This allows authenticated attackers to change passwords for arbitrary accounts by providing a target account ID and the current password of that account in the request body of the 'PUT /hr/pass' endpoint.
Recommendations
Update vhr to a version beyond commit 03abbd3.
As a temporary mitigation, restrict access to the 'PUT /hr/pass' endpoint.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vhr