An unrestricted upload of file with dangerous type vulnerability in the upload file function of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to execute arbitrary system commands via a malicious file.
References
| Link | Resource |
|---|---|
| https://zuso.ai/advisory/za-2025-07 | Third Party Advisory |
Configurations
History
04 Feb 2026, 14:38
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:scshr:hr_portal:*:*:*:*:*:*:*:* | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
| First Time |
Scshr
Scshr hr Portal |
|
| References | () https://zuso.ai/advisory/za-2025-07 - Third Party Advisory |
Information
Published : 2025-06-06 10:15
Updated : 2026-02-04 14:38
NVD link : CVE-2025-48782
Mitre link : CVE-2025-48782
CVE.ORG link : CVE-2025-48782
JSON object : View
Products Affected
scshr
- hr_portal
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type
