Description
A vulnerability was found in code-projects Human Resource Management System 1.0.1 and classified as critical. This issue affects the function Index of the file \handler\Account.go. The manipulation of the argument user_cookie leads to improper authorization. The exploit has been disclosed to the public and may be used.
Eine kritische Schwachstelle wurde in code-projects Human Resource Management System 1.0.1 gefunden. Hierbei geht es um die Funktion Index der Datei \handler\Account.go. Mittels dem Manipulieren des Arguments user_cookie mit unbekannten Daten kann eine improper authorization-Schwachstelle ausgenutzt werden. Der Exploit steht zur öffentlichen Verfügung.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2025-03-21: | Advisory disclosed |
| 2025-03-21: | VulDB entry created |
| 2025-03-21: | VulDB entry last update |
Credits
hnsjwaxxjsyxgs (VulDB User)
References
github.com/38279/1/issues/1
vuldb.com/?id.300569 (VDB-300569 | code-projects Human Resource Management System Account.go Index improper authorization)
vuldb.com/?ctiid.300569 (VDB-300569 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.517343 (Submit #517343 | codeprojects human resource management 1.0.1 unauthorized access)
github.com/38279/1/issues/1
code-projects.org/