A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.
References
| Link | Resource |
|---|---|
| https://zuso.ai/advisory/za-2025-04 | Third Party Advisory |
Configurations
History
04 Feb 2026, 14:28
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
| References | () https://zuso.ai/advisory/za-2025-04 - Third Party Advisory | |
| CPE | cpe:2.3:a:scshr:hr_portal:*:*:*:*:*:*:*:* | |
| First Time |
Scshr
Scshr hr Portal |
Information
Published : 2025-06-06 10:15
Updated : 2026-02-04 14:28
NVD link : CVE-2025-5192
Mitre link : CVE-2025-5192
CVE.ORG link : CVE-2025-5192
JSON object : View
Products Affected
scshr
- hr_portal
CWE
CWE-306
Missing Authentication for Critical Function
