Soar Cloud System Co., Ltd. HR Portal - SQL Injection
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.6%
exploitation probability
1.6%top 26% of all CVEs
observed exploitation
nono source reports it
The HR Portal of Soar Cloud System fails to filter specific parameters. Remote attackers can inject SQL syntax and obtain all data in the database without privilege.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Soar Cloud System Co., Ltd. · HR Portal