Soar Cloud System Co., Ltd. HR Portal - Arbitrary Code Execution
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 2.0%
exploitation probability
2.0%top 20% of all CVEs
observed exploitation
nono source reports it
The specific function of HR Portal of Soar Cloud System accepts any type of object to be deserialized. Attackers can send malicious serialized objects to execute arbitrary commands.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Soar Cloud System Co., Ltd. · HR Portal