CVE-2025-5192 PUBLISHED

Soar Cloud HRD Human Resource Management System - Missing Authentication for Critical Function

Assigner: ZUSO ART
Reserved: 26.05.2025 Published: 06.06.2025 Updated: 06.06.2025

A missing authentication for critical function vulnerability in the client application of Soar Cloud HRD Human Resource Management System through version 7.3.2025.0408 allows remote attackers to bypass authentication and access application functions.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 9.3

Product Status

Vendor Soar Cloud System CO., LTD.
Product HRD Human Resource Management System
Versions Default: affected
  • affected from 0 to 7.3.2025.0408 (incl.)

References

Problem Types

  • CWE-306 Missing Authentication for Critical Function CWE