Home/Product/scshr hr portal
Product

scshr hr portal

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-5192
<= 7.3.2025.0408
A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management
7.5HIGH
CVE-2025-48784
<= 7.3.2025.0408
A missing authorization vulnerability in Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remo
7.5HIGH
CVE-2025-48783
<= 7.3.2025.0408
An external control of file name or path vulnerability in the delete file function of Soar Cloud HRD Human Resource Management Sys
7.5HIGH
CVE-2025-48782
<= 7.3.2025.0408
An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Mana
9.8CRITICAL
CVE-2025-48781
<= 7.3.2025.0408
An external control of file name or path vulnerability in the download file function of Soar Cloud HRD Human Resource Management S
7.5HIGH
CVE-2025-48780
<= 7.3.2025.0408
A deserialization of untrusted data vulnerability in the download file function of Soar Cloud HRD Human Resource Management System
9.8CRITICAL
CVE-2023-34357
all versions
Soar Cloud Ltd. HR Portal has a weak Password Recovery Mechanism for Forgotten Password. The reset password link sent out through
7.8HIGH
CVE-2021-22855
all versions
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send maliciou
9.8CRITICAL
CVE-2021-22854
all versions
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data
7.5HIGH
CVE-2021-22853
all versions
The HR Portal of Soar Cloud System fails to manage access control. While obtaining user ID, remote attackers can access sensitive
5.4MEDIUM
CVE-2019-10257
<= 2019-03-15
Zucchetti HR Portal through 2019-03-15 allows Directory Traversal. Unauthenticated users can escape outside of the restricted loca
7.5HIGH
threatengine.sh