CVE-2025-1815 Details
Description
A vulnerability, which was classified as critical, was found in pbrong hrms up to 1.0.1. This affects the function HrmsDB of the file \resource\resource.go. The manipulation of the argument user_cookie leads to improper authorization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
A critical vulnerability allowing unauthorized access to user information has been identified in Pbrong Hrms version 1.0.1. The issue resides in the Resource Go file, specifically within the HrmsDB function. The vulnerability arises from inadequate permission verification during database queries, enabling attackers to bypass authorization by manipulating cookies and accessing user data. This flaw can be exploited remotely.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 2, 2025CISA-ADP
Assessed Mar 3, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/A7cc/cve/issues/4 | CISA-ADP | ExploitIssue TrackingTechnical Description |
| https://github.com/A7cc/cve/issues/4 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://github.com/A7cc/cve/issues/4#issue-2877111776 | [email protected] | ExploitIssue TrackingTechnical Description |
| https://vuldb.com/?ctiid.298083 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?id.298083 | [email protected] | AdvisoryContent Wall |
| https://vuldb.com/?submit.506544 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-285 | Improper Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| pbrong hrms | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 3, 2025 | CVE Modified | CISA-ADP |
| Mar 2, 2025 | New CVE Received | [email protected] |
Volerion